Junglewise Threat Intelligence

CVE-2026-57877: GeoVision GV-LPC series format string vulnerability in vlsvr

CVE-2026-57877 · Severity: high · CVSS 8.6 · Published 2026-06-26

Technologies: Geovision Gv-Lpc2211, Geovision Gv-Lpc2011. Vendors: Geovision.

Executive brief

GeoVision license plate recognition cameras contain a security flaw in their login processing component. An unauthenticated attacker can exploit this by sending specially crafted data to the device, potentially causing the camera to crash, leak sensitive information, or allow for memory corruption. This could disrupt security monitoring operations and compromise the integrity of the surveillance hardware.

Technical details

An unauthenticated format string vulnerability (CWE-134) exists in the 'vlsvr' service of GeoVision GV-LPC2011 and GV-LPC2211 devices running firmware version 1.12 and earlier. The flaw is located within the login processing path, where externally controlled input is improperly handled during log message formatting. A remote, unauthenticated attacker can exploit this by sending crafted login data. Successful exploitation can result in information disclosure, memory corruption, or a denial of service (DoS) condition. The vulnerability is addressed in firmware version 1.13.

Affected products

  • GeoVision GV-LPC2011 v1.12 and earlier
  • GeoVision GV-LPC2211 v1.12 and earlier

Timeline

  • 2026-06-26: advisory: NVD publication date
  • 2026-06-26: disclosed: CVE published by GeoVision (CNA)

References

Related threats