CVE-2026-88288

GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a remote user with valid web credentials to read arbitrary files accessible to the root-run web service.

  • Published Sep 10, 2026
  • CVSS 6.5 medium
  • 0.5% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-88288 at the National Vulnerability Database