CVE-2026-88289

GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR service.

  • Published Sep 10, 2026
  • CVSS 7.5 high
  • 0.6% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-88289 at the National Vulnerability Database