CVE-2026-57880: GV-LPC2011/LPC2211 - unauthorized buffer overflow via RTSP Digest username (ssvr)
An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when parsing RTSP Digest authentication fields. A remote attacker may exploit this vulnerability by sending a crafted RTSP request containing overly long authentication data, resulting in memory corruption, denial of service, or potentially arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57880?
The severity of CVE-2026-57880 is critical with a score of 9.8.
How do I fix CVE-2026-57880?
To fix CVE-2026-57880, update the software to version V1.13 or later where the vulnerability is addressed.
What type of vulnerability is CVE-2026-57880?
CVE-2026-57880 is a stack-based buffer overflow vulnerability.
Who is affected by CVE-2026-57880?
CVE-2026-57880 affects users of GeoVision GV-LPC2011 and GV-LPC2211 versions V1.12 and earlier.
Can CVE-2026-57880 be exploited remotely?
Yes, CVE-2026-57880 can be exploited remotely due to its unauthenticated nature.