CVE-2026-57877 Details
Description
An unauthenticated format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper handling of externally controlled input during log message formatting in the login processing path. A remote attacker may exploit this vulnerability by sending crafted login data, potentially causing information disclosure, memory corruption, or a denial of service.
A format string vulnerability has been identified in the vlsvr component of GeoVision GV-LPC2011 and GV-LPC2211 products, all versions through V1.12. This vulnerability allows for unauthenticated remote exploitation, arising from improper management of externally sourced input during the formatting of log messages related to the login process. An attacker could exploit this issue by sending crafted login data, potentially leading to information disclosure, memory corruption, or a denial-of-service condition.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 26, 2026CISA-ADP
Assessed Jun 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.geovision.com.tw/cyber_security.php | GV | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-134 | Use of Externally-Controlled Format String | GV |
Affected Products
| Product | Versions |
|---|---|
| GeoVision GV-LPC2011 | <= V1.12 |
CPE
Remediation
| |
| GeoVision GV-LPC2211 | <= V1.12 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 26, 2026 | CVE Modified | CISA-ADP |
| Jun 26, 2026 | New CVE Received | GV |
Volerion