An unauthenticated
directory traversal vulnerability exists in get_fcont.cgi in GeoVision
GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by
insufficient validation of user-supplied file path input before the requested
file is accessed by the CGI component. A remote attacker may exploit this
vulnerability by sending a crafted request to read arbitrary files accessible
to the affected process, resulting in information disclosure.
References
| Link | Resource |
|---|---|
| https://www.geovision.com.tw/cyber_security.php |
Configurations
No configuration.
History
No history.
Information
Published : 2026-06-26 08:16
Updated : 2026-06-26 16:16
NVD link : CVE-2026-57872
Mitre link : CVE-2026-57872
CVE.ORG link : CVE-2026-57872
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
