CVE-2026-57878
Received Received - Intake
Stack-Based Buffer Overflow in thttpd for GeoVision GV-LPC2011 and GV-LPC2211

Publication date: 2026-06-26

Last updated on: 2026-06-26

Assigner: 0df08a0e-a200-4957-9bb0-084f562506f9

Description
An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing web request parameters in a specific request path. A remote attacker may exploit this vulnerability by sending a crafted HTTP request with overly long input, resulting in memory corruption, denial of service, or potentially arbitrary code execution.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-26
Last Modified
2026-06-26
Generated
2026-06-26
AI Q&A
2026-06-26
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
geovision gv-lpc2011 v1.12
geovision gv-lpc2211 v1.12
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is an unauthenticated stack-based buffer overflow found in the thttpd component of GeoVision GV-LPC2011 and GV-LPC2211 devices running version 1.12 or earlier.

It occurs because the software does not properly check the length of web request parameters in a specific request path, allowing an attacker to send an overly long HTTP request.

Exploiting this flaw can cause memory corruption, which may lead to denial of service or even allow the attacker to execute arbitrary code remotely.

Impact Analysis

If exploited, this vulnerability can have severe impacts including:

  • Denial of Service (DoS) - the device or service may crash or become unresponsive.
  • Memory corruption - which can destabilize the device or software.
  • Potential arbitrary code execution - allowing an attacker to run malicious code remotely without authentication.

These impacts can compromise the availability, integrity, and confidentiality of the affected system.

Mitigation Strategies

To mitigate this vulnerability, it is important to apply any available security updates or patches provided by GeoVision as soon as possible.

GeoVision follows a vulnerability management process that includes prompt release of unscheduled updates for critical vulnerabilities such as this one.

Users should monitor GeoVision's official cybersecurity advisories and update their GV-LPC2011 and GV-LPC2211 devices to the latest firmware versions that address this buffer overflow vulnerability.

Additionally, restricting network access to the affected devices and monitoring for unusual HTTP requests may help reduce exposure until patches are applied.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-57878. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart