CVE-2026-57878: GV-LPC2011/LPC2211 - unauthorized buffer overflow vulnerability (thttpd)
An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing web request parameters in a specific request path. A remote attacker may exploit this vulnerability by sending a crafted HTTP request with overly long input, resulting in memory corruption, denial of service, or potentially arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57878?
CVE-2026-57878 has a severity rating of 9.8, which is classified as critical.
How can I fix CVE-2026-57878?
To fix CVE-2026-57878, upgrade thttpd to a version later than V1.12 that contains the security patch.
What causes the CVE-2026-57878 vulnerability?
CVE-2026-57878 is caused by insufficient bounds checking when processing web request parameters.
Who is affected by CVE-2026-57878?
CVE-2026-57878 affects users of GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier.
What type of attack does CVE-2026-57878 allow?
CVE-2026-57878 allows a remote attacker to perform a stack-based buffer overflow due to the vulnerability.