GeoVision gv-lpc2011是中国GeoVision公司的视频监控设备。 GeoVision GV-LPC2011和GV-LPC2211存在缓冲区错误漏洞,该漏洞源于处理特定请求路径中的Web请求参数时边界检查不足,可能导致未经身份验证的远程攻击者通过发送特制的HTTP请求造成内存损坏、拒绝服务或执行任意代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GeoVision Inc. | GV-LPCLPC2011/2211 | 1.12 |
affected |
1.13 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GeoVision Inc. | GV-LPCLPC2011/2211 | 1.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57881 | 9.8 CRITICAL | GV-LPC2011/LPC2211 - unauthorized stack-based buffer overflow vulnerability (vlsvr) |
| CVE-2026-57879 | 9.8 CRITICAL | GV-LPC2011/LPC2211 - unauthorized buffer overflow via AuthMode/AuthValue path (ssvr) |
| CVE-2026-57880 | 9.8 CRITICAL | GV-LPC2011/LPC2211 - unauthorized buffer overflow via RTSP Digest username (ssvr) |
| CVE-2026-57877 | 8.6 HIGH | GV-LPC2011/LPC2211 - unauthorized format string vulnerability (vlsvr) |
| CVE-2026-57874 | 7.5 HIGH | GV-LPC2011/LPC2211 - unauthorized buffer overflow vulnerability (IEEE8021x_upload.cgi) |
| CVE-2026-57872 | 7.5 HIGH | GV-LPC2011/LPC2211 - unauthorized directory traversal vulnerability (get_fcont.cgi) |
| CVE-2026-57873 | 7.5 HIGH | GV-LPC2011/LPC2211 - unauthorized null pointer dereference vulnerability (IEEE8021x_upload |
| CVE-2026-57876 | 7.5 HIGH | GV-LPC2011/LPC2211 - unauthorized out-of-bounds writing vulnerability (onvif.cgi) |
| CVE-2026-57875 | 7.5 HIGH | GV-LPC2011/LPC2211 - unauthorized null pointer dereference vulnerability in packet parsing |
No comments yet