Description
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly.

The Websocket server can accept various commands coming from localhost. One of them, `connectionInfo` is meant to provide the necessary details to connect to a camera. The handler associated with this command that we call`handle_connection_info` contains multiple instances of string copy that can overflow. The function `handle_connect_info` copies attacker-controlled JSON strings into fixed-size buffers using manual byte-by-byte loops that do not enforce length limits.





#### Buffer Overflow in password field (no key present)
Published: 2026-07-02
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

GeoWebPlayer’s websocket server accepts JSON payloads for the connectionInfo command and copies them into fixed‑size buffers using unchecked byte‑by‑byte loops. This stack‑based buffer overflow (CWE‑120) can overwrite the return address and allows an attacker controlling the JSON input to execute arbitrary code on the host where the websocket server runs. The vulnerability is rated 8.3 on the CVSS scale, indicating a significant potential for privilege escalation and full system compromise when the attacker has local execution rights.

Affected Systems

The flaw resides in GeoVision Inc.’s GeoWebPlayer 1.1.1.0, which is deployed on both 64‑bit Linux and Windows environments. The vendor released GeoWebPlayer 1.1.3.0 that removes the unsafe copy loops and fixes the overflow. Any installation of GeoWebPlayer equal to or older than 1.1.1.0, lacking the patch, is potentially vulnerable.

Risk and Exploitability

This high‑severity vulnerability has an EPSS score of < 1%, suggesting that exploitation attempts are currently rare. Based on the description, the likely attack vector is local; the websocket interface is bound to localhost, so remote attackers must first gain local code execution or compromise a local service that can communicate with the socket. While the risk of remote exploitation is limited, the impact of successful local exploitation is severe, providing full control over the affected machine. The vulnerability is not listed in CISA’s KEV catalog, indicating no publicly documented exploits at this time. Prompt patching remains the best defense.

Generated by OpenCVE AI on July 21, 2026 at 12:30 UTC.

Remediation

Vendor Solution

The vulnerability has been patched with GeoWebPlayer V1.1.3.0


OpenCVE Recommended Actions

  • Upgrade GeoWebPlayer to version 1.1.3.0 or later
  • Disable the connectionInfo command or shut down the websocket service if it is not required for operationict access to the websocket port by configuring firewall rules to allow only trusted hosts or the loopback interface
  • Monitor websocket logs for anomalous traffic and consider disabling the service if it is not needed

Generated by OpenCVE AI on July 21, 2026 at 12:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Description GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. One of them, `connectionInfo` is meant to provide the necessary details to connect to a camera. The handler associated with this command that we call`handle_connection_info` contains multiple instances of string copy that can overflow. The function `handle_connect_info` copies attacker-controlled JSON strings into fixed-size buffers using manual byte-by-byte loops that do not enforce length limits. #### Buffer Overflow in password field (no key present)
Title GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffer overflow vulnerability
First Time appeared Geovision Inc.
Geovision Inc. geowebplayer
Weaknesses CWE-120
CPEs cpe:2.3:a:geovision_inc.:geowebplayer:v1.1.1.0:*:64_bit:*:*:*:*:*
cpe:2.3:a:geovision_inc.:geowebplayer:v1.1.1.0:*:windows:*:*:*:*:*
cpe:2.3:a:geovision_inc.:geowebplayer:v1.1.3.0:*:64_bit:*:*:*:*:*
cpe:2.3:a:geovision_inc.:geowebplayer:v1.1.3.0:*:windows:*:*:*:*:*
Vendors & Products Geovision Inc.
Geovision Inc. geowebplayer
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Geovision Inc. Geowebplayer
cve-icon MITRE

Status: PUBLISHED

Assigner: GV

Published:

Updated: 2026-07-02T12:36:12.891Z

Reserved: 2026-06-24T05:48:05.704Z

Link: CVE-2026-57274

cve-icon Vulnrichment

Updated: 2026-07-02T12:36:06.548Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T12:45:02Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')