Junglewise Threat Intelligence

CVE-2026-57872: GeoVision GV-LPC series directory traversal in get_fcont.cgi

CVE-2026-57872 · Severity: high · CVSS 7.5 · Published 2026-06-26

Technologies: Geovision Gv-Lpc2211, Geovision Gv-Lpc2011. Vendors: Geovision.

Executive brief

GeoVision license plate recognition cameras are affected by a security flaw that allows unauthorized individuals to access internal system files. By sending a specially crafted web request, an attacker can bypass security restrictions to read sensitive information stored on the device. This could lead to the exposure of configuration data or other private files, potentially compromising the security of the surveillance network.

Technical details

A directory traversal vulnerability exists in the get_fcont.cgi component of GeoVision GV-LPC2011 and GV-LPC2211 firmware versions V1.12 and earlier. The issue stems from insufficient validation of user-supplied file path input before the CGI component accesses the requested file. An unauthenticated remote attacker can exploit this by sending a crafted HTTP request containing path traversal sequences (e.g., ../) to read arbitrary files accessible to the web server process. This vulnerability is addressed in firmware version V1.13.

Affected products

  • GeoVision GV-LPC2011 V1.12 and earlier
  • GeoVision GV-LPC2211 V1.12 and earlier

Timeline

  • 2026-06-26: disclosed
  • 2026-06-26: advisory
  • 2026-06-26: patched: Fixed in version 1.13

References

Related threats