CVE-2026-88278
GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations.
- Published Sep 10, 2026
- CVSS 9.8 critical
- 0.5% chance of exploitation in the next 30 days (EPSS)