CVE-2026-57872Disclosure

LOWCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (9 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

An unauthenticated directory traversal vulnerability exists in get_fcont.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient validation of user-supplied file path input before the requested file is accessed by the CGI component. A remote attacker may exploit this vulnerability by sending a crafted request to read arbitrary files accessible to the affected process, resulting in information disclosure.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 10 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 10 signals
  • Disclosure: 9 classified signals
  • Peaked at 9 mentions on most recent observed day (2026-07-21)
  • 10 total mentions across 2 days

Deep dive

Activity timeline10 mentions / 2d
02579Mentions · 2026-07-02: 1Mentions · 2026-07-21: 9Active Exploitation · 2026-07-21: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-21: 907-0207-21
Signal classification2 categories
Disclosure
990.0%
Active Exploitation
110.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-021
Disclosure1
2026-07-219
Active Exploitation1Disclosure8
Full discourse10 posts
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2026-57872: GV-LPC2011/LPC2211 - unauthorized directory traversal vulnerability (get_fcont.cgi) Critical Vulnerability Alert! GeoVision is affected by CVE-2026-57872. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://darkeye.org/vuln/cve/CVE-2026-57872 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-57872" Search Dork: app="GeoVision" Exposure: 322.6k instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJHZW9WaXNpb24i&t=all&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260702 #Infosec #CyberSecurity #ZoomEye #DarkEye

    Post summary

    A new unauthorized directory traversal vulnerability (CVE‑2026‑57872) affecting GeoVision GV‑LPC2011/LPC2211 devices has been disclosed, with full details available via DarkEye and exposure identified on ZoomEye.

    010030175.0K
    12.7K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    09:11 UTC: First exploit attempt in the wild. 0day Intel: 🚨 CVE-2026-57872: GV-LPC2011/LPC2211 - unauthorized directory traversal vulnera

    Post summary

    CVE-2026-57872, a directory traversal flaw in GV‑LPC2011/LPC2211, has been targeted in a first reported wild exploit attempt at 09:11 UTC.

    1000047
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    06:25 UTC: Thread live on @lyrie_ai. 0day Intel: 🚨 CVE-2026-57872: GV-LPC2011/LPC2211 - unauthorized directory traversal vulnera

    Post summary

    The tweet announces a zero‑day CVE-2026-57872 for GV‑LPC2011/LPC2211 devices, highlighting an unauthorized directory traversal flaw, with no PoC or patch details disclosed.

    1000036
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    06:22 UTC: GPT-5 enrichment complete. 59 words. 1 citations. 0day Intel: 🚨 CVE-2026-57872: GV-LPC2011/LPC2211 - unauthorized directory traversal vulnera

    Post summary

    The tweet announces the discovery of CVE-2026-57872, describing an unauthorized directory traversal flaw in GV-LPC2011/LPC2211, but does not provide a PoC, exploit code, reported exploitation, or patch information.

    1000028
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    06:14 UTC: Lyrie Sentinel flagged it. 0day Intel: 🚨 CVE-2026-57872: GV-LPC2011/LPC2211 - unauthorized directory traversal vulnera

    Post summary

    The post announces a newly discovered CVE-2026-57872 affecting GV-LPC2011/LPC2211 devices with an unauthorized directory traversal flaw, but no PoC, exploit, or mitigation details are provided.

    1000023
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    06:11 UTC: CVE-2026-57872 disclosed. 🚨 CVE-2026-57872: GV-LPC2011/LPC2211 - unauthorized directory traversal vulnerability (getfcont.cgi) Critical Vulnera

    Post summary

    The tweet announces the disclosure of CVE-2026-57872, describing a directory traversal vulnerability in GV-LPC2011/LPC2211’s getfcont.cgi, with no PoC, exploit, or patch information provided.

    1000036
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Full Tweet 🚨 CVE-2026-57872: GV-LPC2011/LPC2211 - unauthorized directory traversal vulnerability (getfcont.cgi) 0day Intel: 🚨 CVE-2026-57872: GV-LPC2011/LPC2211 - unauthorized directory traversal vulnera

    Post summary

    The tweet announces the new CVE-2026-57872, identifying it as a directory traversal flaw in GV-LPC2011/LPC2211 with limited technical context and no evidence of exploitation or mitigation.

    1000027
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Source: X search for CVE-2026 critical Posted: 2026-07-02T06:11:40.000Z Likes: 14 0day Intel: 🚨 CVE-2026-57872: GV-LPC2011/LPC2211 - unauthorized directory traversal vulnera

    Post summary

    A new zero‑day vulnerability (CVE‑2026‑57872) in GV‑LPC2011/LPC2211, allowing unauthorized directory traversal, has been disclosed.

    1000028
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-57872: 🚨 CVE-2026-57872: GV-LPC2011/LPC2211 - unauthorized directory traversal vulnerability (getfcont.cgi) Critical Vulnerability Alert! GeoVision is affected by CVE-2026-57872. Full Vulnerability Details & Analysis at DarkEye: 🔗 🔍…

    Post summary

    The message announces the discovery of CVE-2026-57872, an unauthorized directory traversal flaw in GeoVision’s GV-LPC2011/LPC2211 devices, and provides a link to detailed analysis on DarkEye.

    1000031
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    0day Intel: 🚨 CVE-2026-57872: GV-LPC2011/LPC2211 - unauthorized directory traversal vulnera

    Post summary

    A new zero‑day CVE‑2026‑57872, allowing unauthorized directory traversal in GV‑LPC2011/LPC2211, has been disclosed.

    1000021
    326 followersView on X

Explore more