Junglewise Threat Intelligence

CVE-2026-57880: GeoVision GV-LPC2011 and GV-LPC2211 stack overflow in ssvr

CVE-2026-57880 · Severity: critical · CVSS 9.8 · Published 2026-06-26

Technologies: Geovision Gv-Lpc2211, Geovision Gv-Lpc2011. Vendors: Geovision.

Executive brief

GeoVision license plate recognition cameras are affected by a critical security flaw that allows an unauthorized person to take control of the device over the network. By sending a specially crafted request, an attacker can crash the camera's software or execute malicious code, potentially leading to unauthorized surveillance or a foothold in the corporate network. This issue affects models GV-LPC2011 and GV-LPC2211 running firmware version 1.12 or older.

Technical details

A stack-based buffer overflow vulnerability (CWE-121) exists in the 'ssvr' service of GeoVision GV-LPC2011 and GV-LPC2211 devices. The flaw is rooted in insufficient bounds checking when the service parses RTSP Digest authentication fields. A remote, unauthenticated attacker can exploit this by sending a crafted RTSP request containing excessively long authentication data. Successful exploitation can lead to memory corruption, allowing for arbitrary code execution or a denial-of-service (DoS) condition. The vulnerability is addressed in firmware version 1.13.

Affected products

  • GeoVision GV-LPC2011 V1.12 and earlier
  • GeoVision GV-LPC2211 V1.12 and earlier

Timeline

  • 2026-06-26: advisory: NVD publication date
  • 2026-06-26: disclosed: CVE published by GeoVision (CNA)

References

Related threats