CVE-2026-57873: GV-LPC2011/LPC2211 - unauthorized null pointer dereference vulnerability (IEEE8021x_upload.cgi)
An unauthenticated NULL pointer dereference vulnerability exists in IEEE8021xupload.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper validation of multipart upload headers when processing certificate-related upload fields. A remote attacker may exploit this vulnerability by sending a malformed multipart request, causing the affected CGI process to crash and resulting in a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57873?
The severity of CVE-2026-57873 is high with a CVSS score of 7.5.
How do I fix CVE-2026-57873?
To fix CVE-2026-57873, update the GeoVision GV-LPC2011 and GV-LPC2211 to version 1.13 or later.
What is the impact of CVE-2026-57873?
CVE-2026-57873 could allow an unauthorized remote attacker to exploit a null pointer dereference, potentially leading to a denial of service.
Which software is affected by CVE-2026-57873?
CVE-2026-57873 affects GeoVision GV-LPC2011 and GV-LPC2211 versions V1.12 and earlier.
Is authentication required to exploit CVE-2026-57873?
No, CVE-2026-57873 can be exploited without authentication.