Security Digest: June 26, 2026 - 8 Critical Vulnerabilities
Today’s most urgent threats include three critical remote-code-execution vulnerabilities in GeoVision GV-LPC2011/GV-LPC2211 devices, plus high-severity issues in Node.js, WSO2 API Manager, and the Setracker2 Android app. If you run any affected systems, patch or isolate them now—especially internet-facing devices and services.
· 9 min read
Urgent Security Digest: GeoVision, Node.js, WSO2, and Mobile App Flaws Demand Immediate Action
Executive Summary
Today’s most urgent threats include three critical remote-code-execution vulnerabilities in GeoVision GV-LPC2011/GV-LPC2211 devices, plus high-severity issues in Node.js, WSO2 API Manager, and the Setracker2 Android app. If you run any affected systems, patch or isolate them now—especially internet-facing devices and services.
The GeoVision flaws are the most dangerous because they are unauthenticated and can lead to full device compromise. Separately, Node.js TLS and WebCrypto issues may break trust boundaries or crash services, while the WSO2 and Setracker2 bugs can expose internal requests or user sessions.
Critical Vulnerabilities
CVE-2026-57881: GeoVision vlsvr stack-based buffer overflow
- Impact: A remote attacker can send crafted login data to trigger memory corruption, denial of service, or potentially arbitrary code execution.
- Affected Systems: GeoVision GV-LPC2011 and GV-LPC2211 running V1.12 and earlier.
- Immediate Action: Treat affected devices as high risk. Remove internet exposure immediately and apply vendor remediation as soon as available.
- Mitigation: Restrict access to trusted networks only; place behind VPN/firewall; monitor for unexpected login attempts and device instability.
CVE-2026-57880: GeoVision ssvr RTSP Digest authentication overflow
- Impact: Crafted RTSP requests with oversized authentication data may cause memory corruption, service crash, or remote code execution.
- Affected Systems: GeoVision GV-LPC2011 and GV-LPC2211 running V1.12 and earlier.
- Immediate Action: Block RTSP access from untrusted networks and isolate exposed devices until patched.
- Mitigation: Disable RTSP where not required; segment surveillance networks; apply firmware updates from GeoVision.
CVE-2026-57879: GeoVision ssvr RTSP custom authentication overflow
- Impact: A remote attacker can exploit malformed RTSP requests to corrupt memory, crash the service, or potentially execute code.
- Affected Systems: GeoVision GV-LPC2011 and GV-LPC2211 running V1.12 and earlier.
- Immediate Action: Assume exposure is exploitable if the device is reachable from outside your trusted network.
- Mitigation: Restrict inbound RTSP traffic; rotate credentials; update firmware and confirm the fix is applied.
CVE-2026-50741: Bypass of prior fix via plugin ID or XML-RPC
- Impact: Attackers can bypass a previous security fix, potentially restoring access that should have been blocked.
- Affected Systems: Systems affected by CVE-2026-34916 and using the related plugin/XML-RPC paths.
- Immediate Action: Reassess any system you believed was already remediated; the prior fix may not be sufficient.
- Mitigation: Apply the latest vendor patch; temporarily disable or restrict XML-RPC and plugin management endpoints if possible.
CVE-2026-2053: WSO2 API Manager WS-Addressing request destination control
- Impact: An unauthenticated attacker can manipulate server-initiated requests to target arbitrary destinations, enabling access to internal services.
- Affected Systems: WSO2 API Manager deployments processing WS-Addressing headers.
- Immediate Action: Patch immediately and review outbound request controls and network egress restrictions.
- Mitigation: Enforce strict input validation, limit outbound destinations, and block access to internal-only resources from the API Manager.
CVE-2026-48618: Node.js TLS hostname normalization bypass
- Impact: Unicode dot separator handling can cause a wildcard-depth authentication bypass, weakening TLS trust checks.
- Affected Systems: All supported release lines: Node.js 22, Node.js 24, and Node.js 26.
- Immediate Action: Upgrade Node.js immediately across all production and CI environments.
- Mitigation: Update to a fixed release; validate certificate checks in applications that rely on hostname matching.
CVE-2026-9221: Setracker2 MD5 signature weakness exposes session IDs
- Impact: Attackers may reverse the signature, recover session IDs, and impersonate legitimate users via the REST API.
- Affected Systems: Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and earlier.
- Immediate Action: Force app updates and invalidate active sessions where possible.
- Mitigation: Replace MD5-based signing, rotate credentials/tokens, and monitor for suspicious API activity.
CVE-2026-48933: Node.js WebCrypto large-input crash
- Impact: A large input to
subtle.encrypt()can crash the Node.js process, causing denial of service. - Affected Systems: All supported release lines: Node.js 22, Node.js 24, and Node.js 26.
- Immediate Action: Patch Node.js and review any code paths that accept unbounded crypto input.
- Mitigation: Apply vendor updates; add input size limits; restart and isolate affected services if crashes are observed.
Previously Alerted
- CVE-2026-57878: CVE-2026-57878 Security Alert: CRITICAL Vulnerability
What to Do Now
- Patch or isolate internet-facing systems first, starting with GeoVision devices and any exposed WSO2 or Node.js services.
- Block unnecessary remote access to RTSP, XML-RPC, admin panels, and mobile/API endpoints.
- Rotate credentials and invalidate sessions where session theft or authentication bypass is possible.
- Verify versions against the affected ranges: GeoVision
V1.12 and earlier; Node.js22/24/26; Setracker23.1.5 and earlier.
Verification steps: confirm firmware/package versions, check whether affected services are reachable from the internet, and review logs for unusual RTSP, login, XML-RPC, or outbound request activity.
Monitoring recommendations: watch for device crashes, unexpected restarts, outbound connections to unfamiliar hosts, authentication anomalies, and spikes in RTSP or API errors.
Related Resources
- Internal blog posts: upcoming analysis on GeoVision exposure, Node.js update guidance, and WSO2 hardening recommendations.
- Official vendor advisories: GeoVision security updates, Node.js release advisories, WSO2 security bulletin, and Setracker2 app update notices.