Junglewise Threat Intelligence

CVE-2026-57876: GeoVision GV-LPC series out-of-bounds write in onvif.cgi

CVE-2026-57876 · Severity: high · CVSS 7.5 · Published 2026-06-26

Technologies: Geovision Gv-Lpc2211, Geovision Gv-Lpc2011. Vendors: Geovision.

Executive brief

GeoVision license plate recognition cameras are affected by a security flaw that allows an unauthenticated attacker to crash the device. By sending a specially crafted web request, an attacker can cause the camera to stop functioning, leading to a denial of service. This could disrupt security monitoring and automated gate or parking operations that rely on these cameras.

Technical details

An unauthenticated out-of-bounds write vulnerability exists in the onvif.cgi component of GeoVision GV-LPC2011 and GV-LPC2211 cameras running firmware V1.12 and earlier. The flaw is rooted in insufficient bounds checking when processing HTTP request body data. A remote, unauthenticated attacker can exploit this by sending a crafted HTTP request with excessive input, leading to memory corruption. Successful exploitation results in a denial of service (DoS) condition. The vulnerability is addressed in firmware version 1.13.

Affected products

  • GeoVision GV-LPC2011 V1.12 and earlier
  • GeoVision GV-LPC2211 V1.12 and earlier

Timeline

  • 2026-06-26: disclosed
  • 2026-06-26: advisory
  • 2026-06-26: patched: Fixed in version 1.13

References

Related threats