Junglewise Threat Intelligence

CVE-2026-57275: GeoVision GeoWebPlayer stack buffer overflow in connectionInfo handler

CVE-2026-57275 · Severity: high · CVSS 8.3 · Published 2026-07-02

Technologies: Geovision GeoWebPlayer. Vendors: Geovision.

Executive brief

GeoWebPlayer is a browser-based plugin used to view video feeds from GeoVision security cameras and management systems. A security flaw allows an attacker to take control of a user's computer if the user visits a malicious website while the plugin is active. This could lead to unauthorized access to camera feeds, data theft, or a total compromise of the workstation.

Technical details

A stack-based buffer overflow exists in the GeoWebPlayer (v1.1.1.0) WebSocket server, specifically within the 'handle_connection_info' function. The vulnerability is caused by a manual byte-by-byte copy loop that fails to validate the length of the 'username' JSON field before copying it into a fixed-size 128-byte buffer (when a 'key' is present). An attacker can exploit this by hosting a malicious webpage that sends a specially crafted WebSocket message to the local GeoWebPlayer service. Successful exploitation can lead to arbitrary code execution with the privileges of the plugin. The issue is addressed in version 1.1.3.0.

Affected products

  • GeoVision Inc. GeoWebPlayer (Web Plugin / WS Player) 1.1.1.0

Timeline

  • 2026-03-25: other: Initial vendor contact
  • 2026-04-21: disclosed: Vendor disclosure
  • 2026-04-28: patched: Vendor patch release
  • 2026-07-01: advisory: Public release by Talos

References

Related threats