7.5
CVE-2026-57875
- EPSS 1.44%
- Veröffentlicht 26.06.2026 07:17:14
- Zuletzt bearbeitet 26.06.2026 16:16:36
- CVE-Watchlists
- Unerledigt
GV-LPC2011/LPC2211 - unauthorized null pointer dereference vulnerability in packet parsing
An unauthenticated NULL pointer dereference vulnerability exists in the HTTP request parsing logic of multiple CGI components in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper validation of required HTTP request metadata before it is used by the affected components. A remote attacker may exploit this vulnerability by sending a specially crafted HTTP request, causing the affected process to crash and resulting in a denial of service.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerGeoVision Inc.
≫
Produkt
GV-LPCLPC2011/2211
Default Statusunaffected
Version
1.12
Status
affected
Version
1.13
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.44% | 0.704 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 0df08a0e-a200-4957-9bb0-084f562506f9 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-476 NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
https://www.geovision.com.tw/cyber_security.php