CVE-2026-57879: GV-LPC2011/LPC2211 - unauthorized buffer overflow via AuthMode/AuthValue path (ssvr)
An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing RTSP custom authentication data. A remote attacker may exploit this vulnerability by sending a crafted RTSP request, resulting in memory corruption, denial of service, or potentially arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57879?
The severity of CVE-2026-57879 is critical with a CVSS score of 9.8.
How do I fix CVE-2026-57879?
To fix CVE-2026-57879, update to the latest version of GeoVision GV-LPC2011 and GV-LPC2211 software that addresses this vulnerability.
What type of vulnerability is CVE-2026-57879?
CVE-2026-57879 is a stack-based buffer overflow vulnerability.
Who is affected by CVE-2026-57879?
CVE-2026-57879 affects GeoVision GV-LPC2011 and GV-LPC2211 systems running version 1.12 and earlier.
How can an attacker exploit CVE-2026-57879?
An attacker can exploit CVE-2026-57879 by sending specially crafted RTSP custom authentication data to the vulnerable devices.