GeoVision GV-LPC2011/LPC2211

18 known vulnerabilities in GeoVision GV-LPC2011/LPC2211, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-88290 CVSS 7.5 high GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay…
  • CVE-2026-88289 CVSS 7.5 high GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack…
  • CVE-2026-88288 CVSS 6.5 medium GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a remote user with valid web…
  • CVE-2026-88287 CVSS 7.5 high GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens in unauthenticated ONVIF WS-Discovery Probe requests, allowing a…
  • CVE-2026-88286 CVSS 7.5 high GeoVision GV-LPC2211 V1.13 improperly manages PTZ connection state, allowing an unauthenticated remote client to block the accept loop and…
  • CVE-2026-88285 CVSS 9.4 critical GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve…
  • CVE-2026-88284 CVSS 4.9 medium GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF SetUser requests, allowing an authenticated administrator to…
  • CVE-2026-88283 CVSS 4.9 medium GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF CreateUsers requests, allowing an authenticated administrator to…
  • CVE-2026-88281 CVSS 4.9 medium GeoVision GV-LPC2211 V1.13 fails to limit repeated Username elements in ONVIF DeleteUsers requests, allowing an authenticated…
  • CVE-2026-88280 CVSS 4.9 medium GeoVision GV-LPC2211 V1.13 copies an oversized ONVIF SetUser password into a fixed stack field, allowing an authenticated administrator to…
  • CVE-2026-88279 CVSS 4.9 medium GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers username or password values into fixed stack fields, allowing an…
  • CVE-2026-88275 CVSS 7.2 high GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to execute arbitrary commands as root when…
  • CVE-2026-88274 CVSS 7.2 high GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless SSID containing shell syntax to execute arbitrary commands as root.
  • CVE-2026-88273 CVSS 7.2 high GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a sourced shell configuration assignment and…
  • CVE-2026-88272 CVSS 7.2 high GeoVision GV-LPC2211 V1.13 allows an administrator-controlled username containing shell metacharacters to be executed as arbitrary root…
  • CVE-2026-88271 CVSS 8.8 high GeoVision GV-LPC2211 V1.13 allows a Guest user to overwrite device configuration and replace the administrator password through SSVR.
  • CVE-2026-88270 CVSS 6.5 medium GeoVision GV-LPC2211 V1.13 allows a Guest user to enter SSVR firmware-upgrade mode and disrupt live services before any firmware image is…
  • CVE-2026-88269 CVSS 6.5 medium GeoVision GV-LPC2211 V1.13 allows a Guest user to retrieve persistent device configuration containing plaintext administrative and user…