PT-2026-52669 · Geovision · Gv-Lpclpc2011/2211

Published

2026-06-26

·

Updated

2026-06-26

·

CVE-2026-57872

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
An unauthenticated directory traversal vulnerability exists in get fcont.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient validation of user-supplied file path input before the requested file is accessed by the CGI component. A remote attacker may exploit this vulnerability by sending a crafted request to read arbitrary files accessible to the affected process, resulting in information disclosure.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57872

Affected Products

Gv-Lpclpc2011/2211