CVE-2026-57876: GV-LPC2011/LPC2211 - unauthorized out-of-bounds writing vulnerability (onvif.cgi)
An unauthenticated out-of-bounds write vulnerability exists in onvif.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing HTTP request body data. A remote attacker may exploit this vulnerability by sending a crafted request with excessive input, causing memory corruption and resulting in a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57876?
The severity of CVE-2026-57876 is rated as high, with a score of 7.5.
How do I fix CVE-2026-57876?
To fix CVE-2026-57876, it is recommended to update GeoVision GV-LPC2011 and GV-LPC2211 to version V1.13 or later.
What kind of vulnerability is CVE-2026-57876?
CVE-2026-57876 is an unauthorized out-of-bounds writing vulnerability affecting onvif.cgi.
Who is affected by CVE-2026-57876?
CVE-2026-57876 affects users of GeoVision GV-LPC2011 and GV-LPC2211 who are using versions V1.12 and earlier.
Can CVE-2026-57876 be exploited remotely?
Yes, CVE-2026-57876 can be exploited remotely by an attacker sending a crafted HTTP request.