CVE-2026-57872: GV-LPC2011/LPC2211 - unauthorized directory traversal vulnerability (get_fcont.cgi)
An unauthenticated directory traversal vulnerability exists in getfcont.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient validation of user-supplied file path input before the requested file is accessed by the CGI component. A remote attacker may exploit this vulnerability by sending a crafted request to read arbitrary files accessible to the affected process, resulting in information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57872?
The severity of CVE-2026-57872 is classified as high with a CVSS score of 7.5.
What type of vulnerability is CVE-2026-57872?
CVE-2026-57872 is an unauthorized directory traversal vulnerability found in GeoVision GV-LPC2011 and GV-LPC2211.
How do I fix CVE-2026-57872?
To fix CVE-2026-57872, update GeoVision GV-LPC2011 or GV-LPC2211 to version 1.12 or later.
What causes the vulnerability in CVE-2026-57872?
The vulnerability in CVE-2026-57872 is caused by insufficient validation of user-supplied file path input in the get_fcont.cgi component.
Which software is affected by CVE-2026-57872?
CVE-2026-57872 affects GeoVision GV-LPC2011 and GV-LPC2211 models running version 1.12 and earlier.