Junglewise Threat Intelligence

CVE-2026-57878: GeoVision GV-LPC series stack-based buffer overflow in thttpd

CVE-2026-57878 · Severity: critical · CVSS 9.8 · Published 2026-06-26

Technologies: Geovision Gv-Lpc2211, Geovision Gv-Lpc2011. Vendors: Geovision.

Executive brief

GeoVision license plate recognition cameras contain a critical security flaw in their web server component. An attacker can exploit this vulnerability over the network without needing a password to crash the device or potentially take full control of the camera. This could lead to a complete loss of video surveillance, unauthorized access to sensitive visual data, or the device being used as a foothold to attack other parts of the corporate network.

Technical details

A stack-based buffer overflow vulnerability (CWE-121) exists in the thttpd web server component of GeoVision GV-LPC2011 and GV-LPC2211 license plate recognition cameras. The flaw is rooted in insufficient bounds checking when processing web request parameters at a specific request path. A remote, unauthenticated attacker can exploit this by sending a specially crafted HTTP request containing overly long input strings. Successful exploitation can lead to memory corruption, resulting in a denial-of-service (DoS) condition or arbitrary code execution with the privileges of the web server. The vulnerability is addressed in firmware version 1.13.

Affected products

  • GeoVision GV-LPC2011 V1.12 and earlier
  • GeoVision GV-LPC2211 V1.12 and earlier

Timeline

  • 2026-06-26: advisory: NVD publication date
  • 2026-06-26: disclosed: CVE record published by GeoVision (CNA)

References

Related threats