GeoVision gv-lpc2011是中国GeoVision公司的视频监控设备。 GeoVision GV-LPCLPC2011/2211 V1.12及之前版本存在格式化字符串错误漏洞,该漏洞源于登录处理路径中日志消息格式化时对外部控制输入处理不当,可能导致远程攻击者发送特制登录数据,造成信息泄露、内存损坏或拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GeoVision Inc. | GV-LPCLPC2011/2211 | 1.12 |
affected |
1.13 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GeoVision Inc. | GV-LPCLPC2011/2211 | 1.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57881 | 9.8 CRITICAL | GV-LPC2011/LPC2211 - unauthorized stack-based buffer overflow vulnerability (vlsvr) |
| CVE-2026-57879 | 9.8 CRITICAL | GV-LPC2011/LPC2211 - unauthorized buffer overflow via AuthMode/AuthValue path (ssvr) |
| CVE-2026-57880 | 9.8 CRITICAL | GV-LPC2011/LPC2211 - unauthorized buffer overflow via RTSP Digest username (ssvr) |
| CVE-2026-57878 | 9.8 CRITICAL | GV-LPC2011/LPC2211 - unauthorized buffer overflow vulnerability (thttpd) |
| CVE-2026-57874 | 7.5 HIGH | GV-LPC2011/LPC2211 - unauthorized buffer overflow vulnerability (IEEE8021x_upload.cgi) |
| CVE-2026-57872 | 7.5 HIGH | GV-LPC2011/LPC2211 - unauthorized directory traversal vulnerability (get_fcont.cgi) |
| CVE-2026-57873 | 7.5 HIGH | GV-LPC2011/LPC2211 - unauthorized null pointer dereference vulnerability (IEEE8021x_upload |
| CVE-2026-57876 | 7.5 HIGH | GV-LPC2011/LPC2211 - unauthorized out-of-bounds writing vulnerability (onvif.cgi) |
| CVE-2026-57875 | 7.5 HIGH | GV-LPC2011/LPC2211 - unauthorized null pointer dereference vulnerability in packet parsing |
No comments yet