An unauthenticated
format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and
GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper handling
of externally controlled input during log message formatting in the login
processing path. A remote attacker may exploit this vulnerability by sending
crafted login data, potentially causing information disclosure, memory
corruption, or a denial of service.
References
| Link | Resource |
|---|---|
| https://www.geovision.com.tw/cyber_security.php |
Configurations
No configuration.
History
26 Jun 2026, 08:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-26 08:16
Updated : 2026-06-26 16:16
NVD link : CVE-2026-57877
Mitre link : CVE-2026-57877
CVE.ORG link : CVE-2026-57877
JSON object : View
Products Affected
No product.
CWE
CWE-134
Use of Externally-Controlled Format String
