Junglewise Threat Intelligence

CVE-2026-57873: GeoVision GV-LPC series NULL pointer dereference in IEEE8021x_upload.cgi

CVE-2026-57873 · Severity: high · CVSS 7.5 · Published 2026-06-26

Technologies: Geovision Gv-Lpc2211, Geovision Gv-Lpc2011. Vendors: Geovision.

Executive brief

GeoVision license plate recognition cameras are affected by a security flaw that allows an unauthenticated attacker to crash the device remotely. By sending a specially crafted web request to the camera's certificate upload component, an attacker can trigger a system failure, leading to a total loss of availability for surveillance and monitoring operations. This could be used to disable security cameras before or during a physical security breach.

Technical details

An unauthenticated NULL pointer dereference vulnerability exists in the IEEE8021x_upload.cgi component of GeoVision GV-LPC2011 and GV-LPC2211 cameras. The issue stems from improper validation of multipart upload headers when the CGI process handles certificate-related upload fields. A remote, unauthenticated attacker can exploit this by sending a malformed multipart request, causing the CGI process to crash. This results in a denial of service (DoS) condition for the camera's web management and potentially its core functions. The vulnerability is addressed in firmware version 1.13.

Affected products

  • GeoVision GV-LPC2011 1.12 and earlier
  • GeoVision GV-LPC2211 1.12 and earlier

Timeline

  • 2026-06-26: disclosed
  • 2026-06-26: advisory
  • 2026-06-26: patched: Fixed in version 1.13

References

Related threats