CVE-2026-57874: GV-LPC2011/LPC2211 - unauthorized buffer overflow vulnerability (IEEE8021x_upload.cgi)
An unauthenticated buffer overflow vulnerability exists in IEEE8021xupload.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when parsing filename values in multipart upload data. A remote attacker may exploit this vulnerability by sending a crafted upload request with overly long input, causing memory corruption and resulting in a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57874?
The severity of CVE-2026-57874 is rated as high with a score of 7.5 on the CVSS scale.
How do I fix CVE-2026-57874?
To fix CVE-2026-57874, update the GeoVision GV-LPC2011 and GV-LPC2211 software to version V1.13 or later.
What type of vulnerability is CVE-2026-57874?
CVE-2026-57874 is classified as a buffer overflow vulnerability.
What causes the CVE-2026-57874 vulnerability?
CVE-2026-57874 is caused by insufficient bounds checking when parsing filename values in multipart upload data.
Can CVE-2026-57874 be exploited remotely?
Yes, CVE-2026-57874 can be exploited remotely by an attacker without authentication.