Junglewise Threat Intelligence

CVE-2026-57267: GeoVision GeoWebPlayer out-of-bounds access in WebSocket server

CVE-2026-57267 · Severity: high · CVSS 8.3 · Published 2026-07-02

Technologies: GeoVision Inc. GeoWebPlayer. Vendors: Geovision.

Executive brief

GeoVision GeoWebPlayer, a component used to enable web-based video management and viewing for surveillance systems, contains a security flaw in how it handles network commands. An attacker could exploit this by tricking a user into visiting a malicious website, potentially allowing the attacker to take control of the surveillance software or disrupt operations. This could lead to unauthorized access to video feeds, data loss, or a complete system takeover.

Technical details

GeoVision GeoWebPlayer (also known as Web Plugin or WS Player) version 1.1.1.0 contains multiple out-of-bounds read and write vulnerabilities (CWE-129) within its WebSocket server functionality. The server accepts commands from localhost but fails to validate the 'index' field provided in JSON messages before using it to access internal arrays and critical sections. By staging a malicious webpage to send specially crafted WebSocket messages, a remote attacker can trigger these out-of-bounds accesses. This can result in the execution of arbitrary code via corrupted function pointers or unauthorized memory access. The vulnerability is addressed in version V1.1.3.0.

Affected products

  • GeoVision Inc. GeoWebPlayer V1.1.1.0

Timeline

  • 2026-07-01: disclosed: Talos published vulnerability report TALOS-2026-2373.
  • 2026-07-02: advisory: NVD published CVE-2026-57267.
  • 2026-07-02: patched: Vendor confirmed version V1.1.3.0 is unaffected.

References

Related threats