Search

Find a vulnerability

Search criteria

    46 vulnerabilities found for GV-LPC2011/LPC2211 by GeoVision Inc.

    CVE-2026-88290 (GCVE-0-2026-88290)

    Vulnerability from nvd โ€“ Published: 2026-09-10 08:26 โ€“ Updated: 2026-09-10 15:04
    VLAI
    Title
    GV-LPC2011/LPC2211 - Unauthenticated VLSVR Slowloris and Memory Resource Exhaustion
    Summary
    GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker resources.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 15:04 UTC
    CWE
    • CWE-400 - Uncontrolled Resource Consumption
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.14 20260903
    Unaffected: 1.14 20260909
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14_20260903:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-10 06:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88290",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T15:04:05.582523Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:04:23.966Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.14 20260903"
                },
                {
                  "status": "unaffected",
                  "version": "1.14 20260909"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14_20260903:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14_20260909:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "datePublic": "2026-09-10T06:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker resources."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker resources."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-227",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-227 Sustained Client Engagement"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-400",
                  "description": "CWE-400 Uncontrolled Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:26:16.134Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GV-LPC2011/LPC2211 - Unauthenticated VLSVR Slowloris and Memory Resource Exhaustion",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88290",
        "datePublished": "2026-09-10T08:26:16.134Z",
        "dateReserved": "2026-09-10T02:56:08.894Z",
        "dateUpdated": "2026-09-10T15:04:23.966Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88289 (GCVE-0-2026-88289)

    Vulnerability from nvd โ€“ Published: 2026-09-10 08:25 โ€“ Updated: 2026-09-10 15:05
    VLAI
    Title
    GV-LPC2011/LPC2211 - Multiple Pre-Authentication Stack Buffer Overflows in VLSVR Request Handlers
    Summary
    GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR service.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 15:04 UTC
    CWE
    • CWE-121 - Stack-based buffer overflow
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.14 20260903
    Unaffected: 1.14 20260909
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14_20260903:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-10 05:57
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88289",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T15:04:54.812636Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:05:16.556Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.14 20260903"
                },
                {
                  "status": "unaffected",
                  "version": "1.14 20260909"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14_20260903:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14_20260909:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "datePublic": "2026-09-10T05:57:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR service."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR service."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121 Stack-based buffer overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:25:41.380Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GV-LPC2011/LPC2211 - Multiple Pre-Authentication Stack Buffer Overflows in VLSVR Request Handlers",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88289",
        "datePublished": "2026-09-10T08:25:41.380Z",
        "dateReserved": "2026-09-10T02:56:07.564Z",
        "dateUpdated": "2026-09-10T15:05:16.556Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88288 (GCVE-0-2026-88288)

    Vulnerability from nvd โ€“ Published: 2026-09-10 08:25 โ€“ Updated: 2026-09-10 15:05
    VLAI
    Title
    GV-LPC2011/LPC2211 - Arbitrary File Read Through BKDownloadLink.cgi Symlink Creation
    Summary
    GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a remote user with valid web credentials to read arbitrary files accessible to the root-run web service.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 15:05 UTC
    CWE
    • CWE-36 - Absolute path traversal
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.13
    Unaffected: 1.14
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88288",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T15:05:41.910103Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:05:55.364Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.13"
                },
                {
                  "status": "unaffected",
                  "version": "1.14"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a remote user with valid web credentials to read arbitrary files accessible to the root-run web service."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a remote user with valid web credentials to read arbitrary files accessible to the root-run web service."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-597",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-597 Absolute Path Traversal"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-36",
                  "description": "CWE-36 Absolute path traversal",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:25:21.248Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GV-LPC2011/LPC2211 - Arbitrary File Read Through BKDownloadLink.cgi Symlink Creation",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88288",
        "datePublished": "2026-09-10T08:25:21.248Z",
        "dateReserved": "2026-09-10T02:56:06.154Z",
        "dateUpdated": "2026-09-10T15:05:55.364Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88287 (GCVE-0-2026-88287)

    Vulnerability from nvd โ€“ Published: 2026-09-10 08:24 โ€“ Updated: 2026-09-10 15:06
    VLAI
    Title
    GV-LPC2011/LPC2211 -ONVIF Discovery Probe Scopes Stack-Frame Overflow Denial of Service
    Summary
    GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens in unauthenticated ONVIF WS-Discovery Probe requests, allowing a remote attacker to corrupt stack control state and crash the discovery process.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 15:06 UTC
    CWE
    • CWE-121 - Stack-based buffer overflow
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.13
    Unaffected: 1.14
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-10 05:50
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88287",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T15:06:30.836787Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:06:51.366Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.13"
                },
                {
                  "status": "unaffected",
                  "version": "1.14"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "datePublic": "2026-09-10T05:50:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens in unauthenticated ONVIF WS-Discovery Probe requests, allowing a remote attacker to corrupt stack control state and crash the discovery process."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens in unauthenticated ONVIF WS-Discovery Probe requests, allowing a remote attacker to corrupt stack control state and crash the discovery process."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121 Stack-based buffer overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:24:57.464Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GV-LPC2011/LPC2211 -ONVIF Discovery Probe Scopes Stack-Frame Overflow Denial of Service",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88287",
        "datePublished": "2026-09-10T08:24:57.464Z",
        "dateReserved": "2026-09-10T02:56:04.083Z",
        "dateUpdated": "2026-09-10T15:06:51.366Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88286 (GCVE-0-2026-88286)

    Vulnerability from nvd โ€“ Published: 2026-09-10 08:24 โ€“ Updated: 2026-09-10 15:07
    VLAI
    Title
    GV-LPC2011/LPC2211 - PTZ Connection-State Accept-Loop Denial of Service
    Summary
    GeoVision GV-LPC2211 V1.13 improperly manages PTZ connection state, allowing an unauthenticated remote client to block the accept loop and prevent new PTZ connections.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 15:07 UTC
    CWE
    • CWE-400 - Uncontrolled Resource Consumption
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.13
    Unaffected: 1.14
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-10 05:48
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88286",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T15:07:12.086663Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:07:23.392Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.13"
                },
                {
                  "status": "unaffected",
                  "version": "1.14"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "datePublic": "2026-09-10T05:48:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.13 improperly manages PTZ connection state, allowing an unauthenticated remote client to block the accept loop and prevent new PTZ connections."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.13 improperly manages PTZ connection state, allowing an unauthenticated remote client to block the accept loop and prevent new PTZ connections."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-227",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-227 Sustained Client Engagement"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-400",
                  "description": "CWE-400 Uncontrolled Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:24:36.472Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GV-LPC2011/LPC2211 - PTZ Connection-State Accept-Loop Denial of Service",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88286",
        "datePublished": "2026-09-10T08:24:36.472Z",
        "dateReserved": "2026-09-10T02:56:04.083Z",
        "dateUpdated": "2026-09-10T15:07:23.392Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88285 (GCVE-0-2026-88285)

    Vulnerability from nvd โ€“ Published: 2026-09-10 08:24 โ€“ Updated: 2026-09-10 15:08
    VLAI
    Title
    GV-LPC2011/LPC2211 - Unauthenticated PTZ Control Service
    Summary
    GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve PTZ information and issue PTZ or raw serial commands.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 15:07 UTC
    CWE
    • CWE-306 - Missing authentication for critical function
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.13
    Unaffected: 1.14
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-10 05:46
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88285",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T15:07:57.078549Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:08:11.408Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.13"
                },
                {
                  "status": "unaffected",
                  "version": "1.14"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "datePublic": "2026-09-10T05:46:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve PTZ information and issue PTZ or raw serial commands."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve PTZ information and issue PTZ or raw serial commands."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-115",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-115 Authentication Bypass"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.4,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "LOW",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "CWE-306 Missing authentication for critical function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:24:15.534Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GV-LPC2011/LPC2211 - Unauthenticated PTZ Control Service",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88285",
        "datePublished": "2026-09-10T08:24:15.534Z",
        "dateReserved": "2026-09-10T02:56:04.083Z",
        "dateUpdated": "2026-09-10T15:08:11.408Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88283 (GCVE-0-2026-88283)

    Vulnerability from nvd โ€“ Published: 2026-09-10 08:23 โ€“ Updated: 2026-09-10 15:11
    VLAI
    Title
    GV-LPC2011/LPC2211 - ONVIF CreateUsers Repeated-Element Stack-Frame Overflow Denial of Service
    Summary
    GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF CreateUsers requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 15:09 UTC
    CWE
    • CWE-121 - Stack-based buffer overflow
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.13
    Unaffected: 1.14
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-10 05:42
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88283",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T15:09:13.336976Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:11:03.404Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.13"
                },
                {
                  "status": "unaffected",
                  "version": "1.14"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "datePublic": "2026-09-10T05:42:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF CreateUsers requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF CreateUsers requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 4.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121 Stack-based buffer overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:23:36.234Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "GV-LPC2011/LPC2211 - ONVIF CreateUsers Repeated-Element Stack-Frame Overflow Denial of Service",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88283",
        "datePublished": "2026-09-10T08:23:36.234Z",
        "dateReserved": "2026-09-10T02:56:04.082Z",
        "dateUpdated": "2026-09-10T15:11:03.404Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88281 (GCVE-0-2026-88281)

    Vulnerability from nvd โ€“ Published: 2026-09-10 08:22 โ€“ Updated: 2026-09-10 15:15
    VLAI
    Title
    GV-LPC2011/LPC2211 - ONVIF DeleteUsers Repeated-Element Stack Overflow Denial of Service
    Summary
    GeoVision GV-LPC2211 V1.13 fails to limit repeated Username elements in ONVIF DeleteUsers requests, allowing an authenticated administrator to overflow a stack array and crash the ONVIF worker.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 15:13 UTC
    CWE
    • CWE-121 - Stack-based buffer overflow
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.13
    Unaffected: 1.14
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-10 05:37
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88281",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T15:13:59.774447Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:15:14.057Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.13"
                },
                {
                  "status": "unaffected",
                  "version": "1.14"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "datePublic": "2026-09-10T05:37:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.13 fails to limit repeated Username elements in ONVIF DeleteUsers requests, allowing an authenticated administrator to overflow a stack array and crash the ONVIF worker."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.13 fails to limit repeated Username elements in ONVIF DeleteUsers requests, allowing an authenticated administrator to overflow a stack array and crash the ONVIF worker."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 4.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121 Stack-based buffer overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:22:48.637Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "GV-LPC2011/LPC2211 - ONVIF DeleteUsers Repeated-Element Stack Overflow Denial of Service",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88281",
        "datePublished": "2026-09-10T08:22:48.637Z",
        "dateReserved": "2026-09-10T02:56:04.082Z",
        "dateUpdated": "2026-09-10T15:15:14.057Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88280 (GCVE-0-2026-88280)

    Vulnerability from nvd โ€“ Published: 2026-09-10 08:22 โ€“ Updated: 2026-09-10 15:17
    VLAI
    Title
    GV-LPC2011/LPC2211 - ONVIF SetUser Stack-Frame Overflow Denial of Service
    Summary
    GeoVision GV-LPC2211 V1.13 copies an oversized ONVIF SetUser password into a fixed stack field, allowing an authenticated administrator to crash the ONVIF worker.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 15:15 UTC
    CWE
    • CWE-121 - Stack-based buffer overflow
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: V1.13
    Unaffected: V1.14
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:v1.13:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-10 05:35
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88280",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T15:15:34.880811Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:17:19.483Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "V1.13"
                },
                {
                  "status": "unaffected",
                  "version": "V1.14"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:v1.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:v1.14:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "datePublic": "2026-09-10T05:35:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.13 copies an oversized ONVIF SetUser password into a fixed stack field, allowing an authenticated administrator to crash the ONVIF worker."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.13 copies an oversized ONVIF SetUser password into a fixed stack field, allowing an authenticated administrator to crash the ONVIF worker."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 4.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121 Stack-based buffer overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:22:34.747Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GV-LPC2011/LPC2211 - ONVIF SetUser Stack-Frame Overflow Denial of Service",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88280",
        "datePublished": "2026-09-10T08:22:34.747Z",
        "dateReserved": "2026-09-10T02:56:04.082Z",
        "dateUpdated": "2026-09-10T15:17:19.483Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88279 (GCVE-0-2026-88279)

    Vulnerability from nvd โ€“ Published: 2026-09-10 08:22 โ€“ Updated: 2026-09-10 15:25
    VLAI
    Title
    GV-LPC2011/LPC2211 - ONVIF CreateUsers Username/Password Stack-Frame Overflow Denial of Service
    Summary
    GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers username or password values into fixed stack fields, allowing an authenticated administrator to crash the ONVIF worker.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 15:21 UTC
    CWE
    • CWE-121 - Stack-based buffer overflow
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.13
    Unaffected: 1.14
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-10 05:32
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88279",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T15:21:55.865736Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:25:30.611Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.13"
                },
                {
                  "status": "unaffected",
                  "version": "1.14"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "datePublic": "2026-09-10T05:32:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers username or password values into fixed stack fields, allowing an authenticated administrator to crash the ONVIF worker."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers username or password values into fixed stack fields, allowing an authenticated administrator to crash the ONVIF worker."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 4.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121 Stack-based buffer overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:22:12.621Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GV-LPC2011/LPC2211 - ONVIF CreateUsers Username/Password Stack-Frame Overflow Denial of Service",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88279",
        "datePublished": "2026-09-10T08:22:12.621Z",
        "dateReserved": "2026-09-10T02:56:04.082Z",
        "dateUpdated": "2026-09-10T15:25:30.611Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88275 (GCVE-0-2026-88275)

    Vulnerability from nvd โ€“ Published: 2026-09-10 08:20 โ€“ Updated: 2026-09-10 15:42
    VLAI
    Title
    GV-LPC2011/LPC2211 - Wireless WPA-PSK Command Injection
    Summary
    GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to execute arbitrary commands as root when wireless configuration is applied.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 15:40 UTC
    CWE
    • CWE-78 - Improper neutralization of special elements used in an OS command ('OS command injection')
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.13
    Unaffected: 1.14
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-10 03:48
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88275",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T15:40:29.885435Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:42:01.680Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.13"
                },
                {
                  "status": "unaffected",
                  "version": "1.14"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "datePublic": "2026-09-10T03:48:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to execute arbitrary commands as root when wireless configuration is applied."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to execute arbitrary commands as root when wireless configuration is applied."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-88",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-88 OS Command Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:20:58.135Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GV-LPC2011/LPC2211 - Wireless WPA-PSK Command Injection",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88275",
        "datePublished": "2026-09-10T08:20:58.135Z",
        "dateReserved": "2026-09-10T02:56:02.025Z",
        "dateUpdated": "2026-09-10T15:42:01.680Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88274 (GCVE-0-2026-88274)

    Vulnerability from nvd โ€“ Published: 2026-09-10 08:20 โ€“ Updated: 2026-09-10 15:49
    VLAI
    Title
    GV-LPC2011/LPC2211 - Wireless SSID Command Injection
    Summary
    GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless SSID containing shell syntax to execute arbitrary commands as root.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 15:47 UTC
    CWE
    • CWE-78 - Improper neutralization of special elements used in an OS command ('OS command injection')
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.13
    Unaffected: 1.14
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88274",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T15:47:12.392120Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:49:07.020Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.13"
                },
                {
                  "status": "unaffected",
                  "version": "1.14"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless SSID containing shell syntax to execute arbitrary commands as root."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless SSID containing shell syntax to execute arbitrary commands as root."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-88",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-88 OS Command Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:20:27.221Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GV-LPC2011/LPC2211 - Wireless SSID Command Injection",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88274",
        "datePublished": "2026-09-10T08:20:27.221Z",
        "dateReserved": "2026-09-10T02:56:02.025Z",
        "dateUpdated": "2026-09-10T15:49:07.020Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88273 (GCVE-0-2026-88273)

    Vulnerability from nvd โ€“ Published: 2026-09-10 08:20 โ€“ Updated: 2026-09-10 15:52
    VLAI
    Title
    GV-LPC2011/LPC2211 - PPPoE Username Shell-Configuration Command Injection
    Summary
    GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a sourced shell configuration assignment and execute arbitrary commands as root.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 15:52 UTC
    CWE
    • CWE-78 - Improper neutralization of special elements used in an OS command ('OS command injection')
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.13
    Unaffected: 1.14
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-10 03:28
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88273",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T15:52:03.236073Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:52:25.823Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.13"
                },
                {
                  "status": "unaffected",
                  "version": "1.14"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "datePublic": "2026-09-10T03:28:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a sourced shell configuration assignment and execute arbitrary commands as root."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a sourced shell configuration assignment and execute arbitrary commands as root."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-88",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-88 OS Command Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:20:07.306Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GV-LPC2011/LPC2211 - PPPoE Username Shell-Configuration Command Injection",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88273",
        "datePublished": "2026-09-10T08:20:07.306Z",
        "dateReserved": "2026-09-10T02:56:02.025Z",
        "dateUpdated": "2026-09-10T15:52:25.823Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88272 (GCVE-0-2026-88272)

    Vulnerability from nvd โ€“ Published: 2026-09-10 08:19 โ€“ Updated: 2026-09-10 17:27
    VLAI
    Title
    GV-LPC2011/LPC2211 - Stored Administrator-Username Command Injection
    Summary
    GeoVision GV-LPC2211 V1.13 allows an administrator-controlled username containing shell metacharacters to be executed as arbitrary root commands when the stored username is later deleted.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 17:23 UTC
    CWE
    • CWE-78 - Improper neutralization of special elements used in an OS command ('OS command injection')
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.13
    Unaffected: 1.14
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-10 03:22
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88272",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T17:23:20.570655Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T17:27:25.963Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.13"
                },
                {
                  "status": "unaffected",
                  "version": "1.14"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "datePublic": "2026-09-10T03:22:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.13 allows an administrator-controlled username containing shell metacharacters to be executed as arbitrary root commands when the stored username is later deleted."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.13 allows an administrator-controlled username containing shell metacharacters to be executed as arbitrary root commands when the stored username is later deleted."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-88",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-88 OS Command Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:19:47.495Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GV-LPC2011/LPC2211 - Stored Administrator-Username Command Injection",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88272",
        "datePublished": "2026-09-10T08:19:47.495Z",
        "dateReserved": "2026-09-10T02:56:02.025Z",
        "dateUpdated": "2026-09-10T17:27:25.963Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88271 (GCVE-0-2026-88271)

    Vulnerability from nvd โ€“ Published: 2026-09-10 08:19 โ€“ Updated: 2026-09-10 17:29
    VLAI
    Title
    GV-LPC2011/LPC2211 - SSVR Guest Configuration Overwrite and Administrative Credential Takeover
    Summary
    GeoVision GV-LPC2211 V1.13 allows a Guest user to overwrite device configuration and replace the administrator password through SSVR.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 17:27 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.13
    Unaffected: 1.14
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-10 03:18
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88271",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T17:27:47.922594Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T17:29:05.605Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.13"
                },
                {
                  "status": "unaffected",
                  "version": "1.14"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "datePublic": "2026-09-10T03:18:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.13 allows a Guest user to overwrite device configuration and replace the administrator password through SSVR."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.13 allows a Guest user to overwrite device configuration and replace the administrator password through SSVR."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-1",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:19:30.491Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GV-LPC2011/LPC2211 - SSVR Guest Configuration Overwrite and Administrative Credential Takeover",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88271",
        "datePublished": "2026-09-10T08:19:30.491Z",
        "dateReserved": "2026-09-10T02:56:02.025Z",
        "dateUpdated": "2026-09-10T17:29:05.605Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88270 (GCVE-0-2026-88270)

    Vulnerability from nvd โ€“ Published: 2026-09-10 08:19 โ€“ Updated: 2026-09-10 17:30
    VLAI
    Title
    GV-LPC2011/LPC2211 - SSVR Guest Firmware-Mode Pre-Validation Service Teardown Denial of Service
    Summary
    GeoVision GV-LPC2211 V1.13 allows a Guest user to enter SSVR firmware-upgrade mode and disrupt live services before any firmware image is validated.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 17:29 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.13
    Unaffected: 1.14
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88270",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T17:29:51.381331Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T17:30:11.233Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.13"
                },
                {
                  "status": "unaffected",
                  "version": "1.14"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University:"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.13 allows a Guest user to enter SSVR firmware-upgrade mode and disrupt live services before any firmware image is validated."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.13 allows a Guest user to enter SSVR firmware-upgrade mode and disrupt live services before any firmware image is validated."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-1",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:19:10.954Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GV-LPC2011/LPC2211 - SSVR Guest Firmware-Mode Pre-Validation Service Teardown Denial of Service",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88270",
        "datePublished": "2026-09-10T08:19:10.954Z",
        "dateReserved": "2026-09-10T02:56:02.025Z",
        "dateUpdated": "2026-09-10T17:30:11.233Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88269 (GCVE-0-2026-88269)

    Vulnerability from nvd โ€“ Published: 2026-09-10 08:18 โ€“ Updated: 2026-09-10 12:50
    VLAI
    Title
    GV-LPC2011/LPC2211 - SSVR Guest Configuration and Credential Disclosure
    Summary
    GeoVision GV-LPC2211 V1.13 allows a Guest user to retrieve persistent device configuration containing plaintext administrative and user credentials through SSVR.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 12:49 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.13
    Unaffected: 1.14
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88269",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T12:49:52.908880Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T12:50:08.057Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.13"
                },
                {
                  "status": "unaffected",
                  "version": "1.14"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.13 allows a Guest user to retrieve persistent device configuration containing plaintext administrative and user credentials through SSVR."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.13 allows a Guest user to retrieve persistent device configuration containing plaintext administrative and user credentials through SSVR."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-1",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:18:50.110Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GV-LPC2011/LPC2211 - SSVR Guest Configuration and Credential Disclosure",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88269",
        "datePublished": "2026-09-10T08:18:50.110Z",
        "dateReserved": "2026-09-10T02:56:02.025Z",
        "dateUpdated": "2026-09-10T12:50:08.057Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88290 (GCVE-0-2026-88290)

    Vulnerability from cvelistv5 โ€“ Published: 2026-09-10 08:26 โ€“ Updated: 2026-09-10 15:04
    VLAI
    Title
    GV-LPC2011/LPC2211 - Unauthenticated VLSVR Slowloris and Memory Resource Exhaustion
    Summary
    GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker resources.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 15:04 UTC
    CWE
    • CWE-400 - Uncontrolled Resource Consumption
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.14 20260903
    Unaffected: 1.14 20260909
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14_20260903:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-10 06:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88290",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T15:04:05.582523Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:04:23.966Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.14 20260903"
                },
                {
                  "status": "unaffected",
                  "version": "1.14 20260909"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14_20260903:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14_20260909:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "datePublic": "2026-09-10T06:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker resources."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker resources."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-227",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-227 Sustained Client Engagement"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-400",
                  "description": "CWE-400 Uncontrolled Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:26:16.134Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GV-LPC2011/LPC2211 - Unauthenticated VLSVR Slowloris and Memory Resource Exhaustion",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88290",
        "datePublished": "2026-09-10T08:26:16.134Z",
        "dateReserved": "2026-09-10T02:56:08.894Z",
        "dateUpdated": "2026-09-10T15:04:23.966Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88289 (GCVE-0-2026-88289)

    Vulnerability from cvelistv5 โ€“ Published: 2026-09-10 08:25 โ€“ Updated: 2026-09-10 15:05
    VLAI
    Title
    GV-LPC2011/LPC2211 - Multiple Pre-Authentication Stack Buffer Overflows in VLSVR Request Handlers
    Summary
    GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR service.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 15:04 UTC
    CWE
    • CWE-121 - Stack-based buffer overflow
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.14 20260903
    Unaffected: 1.14 20260909
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14_20260903:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-10 05:57
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88289",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T15:04:54.812636Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:05:16.556Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.14 20260903"
                },
                {
                  "status": "unaffected",
                  "version": "1.14 20260909"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14_20260903:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14_20260909:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "datePublic": "2026-09-10T05:57:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR service."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR service."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121 Stack-based buffer overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:25:41.380Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GV-LPC2011/LPC2211 - Multiple Pre-Authentication Stack Buffer Overflows in VLSVR Request Handlers",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88289",
        "datePublished": "2026-09-10T08:25:41.380Z",
        "dateReserved": "2026-09-10T02:56:07.564Z",
        "dateUpdated": "2026-09-10T15:05:16.556Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88288 (GCVE-0-2026-88288)

    Vulnerability from cvelistv5 โ€“ Published: 2026-09-10 08:25 โ€“ Updated: 2026-09-10 15:05
    VLAI
    Title
    GV-LPC2011/LPC2211 - Arbitrary File Read Through BKDownloadLink.cgi Symlink Creation
    Summary
    GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a remote user with valid web credentials to read arbitrary files accessible to the root-run web service.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 15:05 UTC
    CWE
    • CWE-36 - Absolute path traversal
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.13
    Unaffected: 1.14
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88288",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T15:05:41.910103Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:05:55.364Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.13"
                },
                {
                  "status": "unaffected",
                  "version": "1.14"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a remote user with valid web credentials to read arbitrary files accessible to the root-run web service."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a remote user with valid web credentials to read arbitrary files accessible to the root-run web service."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-597",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-597 Absolute Path Traversal"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-36",
                  "description": "CWE-36 Absolute path traversal",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:25:21.248Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GV-LPC2011/LPC2211 - Arbitrary File Read Through BKDownloadLink.cgi Symlink Creation",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88288",
        "datePublished": "2026-09-10T08:25:21.248Z",
        "dateReserved": "2026-09-10T02:56:06.154Z",
        "dateUpdated": "2026-09-10T15:05:55.364Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88287 (GCVE-0-2026-88287)

    Vulnerability from cvelistv5 โ€“ Published: 2026-09-10 08:24 โ€“ Updated: 2026-09-10 15:06
    VLAI
    Title
    GV-LPC2011/LPC2211 -ONVIF Discovery Probe Scopes Stack-Frame Overflow Denial of Service
    Summary
    GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens in unauthenticated ONVIF WS-Discovery Probe requests, allowing a remote attacker to corrupt stack control state and crash the discovery process.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 15:06 UTC
    CWE
    • CWE-121 - Stack-based buffer overflow
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.13
    Unaffected: 1.14
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-10 05:50
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88287",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T15:06:30.836787Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:06:51.366Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.13"
                },
                {
                  "status": "unaffected",
                  "version": "1.14"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "datePublic": "2026-09-10T05:50:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens in unauthenticated ONVIF WS-Discovery Probe requests, allowing a remote attacker to corrupt stack control state and crash the discovery process."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens in unauthenticated ONVIF WS-Discovery Probe requests, allowing a remote attacker to corrupt stack control state and crash the discovery process."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121 Stack-based buffer overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:24:57.464Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GV-LPC2011/LPC2211 -ONVIF Discovery Probe Scopes Stack-Frame Overflow Denial of Service",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88287",
        "datePublished": "2026-09-10T08:24:57.464Z",
        "dateReserved": "2026-09-10T02:56:04.083Z",
        "dateUpdated": "2026-09-10T15:06:51.366Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88286 (GCVE-0-2026-88286)

    Vulnerability from cvelistv5 โ€“ Published: 2026-09-10 08:24 โ€“ Updated: 2026-09-10 15:07
    VLAI
    Title
    GV-LPC2011/LPC2211 - PTZ Connection-State Accept-Loop Denial of Service
    Summary
    GeoVision GV-LPC2211 V1.13 improperly manages PTZ connection state, allowing an unauthenticated remote client to block the accept loop and prevent new PTZ connections.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 15:07 UTC
    CWE
    • CWE-400 - Uncontrolled Resource Consumption
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.13
    Unaffected: 1.14
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-10 05:48
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88286",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T15:07:12.086663Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:07:23.392Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.13"
                },
                {
                  "status": "unaffected",
                  "version": "1.14"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "datePublic": "2026-09-10T05:48:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.13 improperly manages PTZ connection state, allowing an unauthenticated remote client to block the accept loop and prevent new PTZ connections."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.13 improperly manages PTZ connection state, allowing an unauthenticated remote client to block the accept loop and prevent new PTZ connections."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-227",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-227 Sustained Client Engagement"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-400",
                  "description": "CWE-400 Uncontrolled Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:24:36.472Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GV-LPC2011/LPC2211 - PTZ Connection-State Accept-Loop Denial of Service",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88286",
        "datePublished": "2026-09-10T08:24:36.472Z",
        "dateReserved": "2026-09-10T02:56:04.083Z",
        "dateUpdated": "2026-09-10T15:07:23.392Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88285 (GCVE-0-2026-88285)

    Vulnerability from cvelistv5 โ€“ Published: 2026-09-10 08:24 โ€“ Updated: 2026-09-10 15:08
    VLAI
    Title
    GV-LPC2011/LPC2211 - Unauthenticated PTZ Control Service
    Summary
    GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve PTZ information and issue PTZ or raw serial commands.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 15:07 UTC
    CWE
    • CWE-306 - Missing authentication for critical function
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.13
    Unaffected: 1.14
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-10 05:46
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88285",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T15:07:57.078549Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:08:11.408Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.13"
                },
                {
                  "status": "unaffected",
                  "version": "1.14"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "datePublic": "2026-09-10T05:46:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve PTZ information and issue PTZ or raw serial commands."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve PTZ information and issue PTZ or raw serial commands."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-115",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-115 Authentication Bypass"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.4,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "LOW",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "CWE-306 Missing authentication for critical function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:24:15.534Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GV-LPC2011/LPC2211 - Unauthenticated PTZ Control Service",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88285",
        "datePublished": "2026-09-10T08:24:15.534Z",
        "dateReserved": "2026-09-10T02:56:04.083Z",
        "dateUpdated": "2026-09-10T15:08:11.408Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88283 (GCVE-0-2026-88283)

    Vulnerability from cvelistv5 โ€“ Published: 2026-09-10 08:23 โ€“ Updated: 2026-09-10 15:11
    VLAI
    Title
    GV-LPC2011/LPC2211 - ONVIF CreateUsers Repeated-Element Stack-Frame Overflow Denial of Service
    Summary
    GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF CreateUsers requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 15:09 UTC
    CWE
    • CWE-121 - Stack-based buffer overflow
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.13
    Unaffected: 1.14
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-10 05:42
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88283",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T15:09:13.336976Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:11:03.404Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.13"
                },
                {
                  "status": "unaffected",
                  "version": "1.14"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "datePublic": "2026-09-10T05:42:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF CreateUsers requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF CreateUsers requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 4.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121 Stack-based buffer overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:23:36.234Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "GV-LPC2011/LPC2211 - ONVIF CreateUsers Repeated-Element Stack-Frame Overflow Denial of Service",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88283",
        "datePublished": "2026-09-10T08:23:36.234Z",
        "dateReserved": "2026-09-10T02:56:04.082Z",
        "dateUpdated": "2026-09-10T15:11:03.404Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88281 (GCVE-0-2026-88281)

    Vulnerability from cvelistv5 โ€“ Published: 2026-09-10 08:22 โ€“ Updated: 2026-09-10 15:15
    VLAI
    Title
    GV-LPC2011/LPC2211 - ONVIF DeleteUsers Repeated-Element Stack Overflow Denial of Service
    Summary
    GeoVision GV-LPC2211 V1.13 fails to limit repeated Username elements in ONVIF DeleteUsers requests, allowing an authenticated administrator to overflow a stack array and crash the ONVIF worker.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 15:13 UTC
    CWE
    • CWE-121 - Stack-based buffer overflow
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.13
    Unaffected: 1.14
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-10 05:37
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88281",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T15:13:59.774447Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:15:14.057Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.13"
                },
                {
                  "status": "unaffected",
                  "version": "1.14"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "datePublic": "2026-09-10T05:37:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.13 fails to limit repeated Username elements in ONVIF DeleteUsers requests, allowing an authenticated administrator to overflow a stack array and crash the ONVIF worker."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.13 fails to limit repeated Username elements in ONVIF DeleteUsers requests, allowing an authenticated administrator to overflow a stack array and crash the ONVIF worker."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 4.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121 Stack-based buffer overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:22:48.637Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "GV-LPC2011/LPC2211 - ONVIF DeleteUsers Repeated-Element Stack Overflow Denial of Service",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88281",
        "datePublished": "2026-09-10T08:22:48.637Z",
        "dateReserved": "2026-09-10T02:56:04.082Z",
        "dateUpdated": "2026-09-10T15:15:14.057Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88280 (GCVE-0-2026-88280)

    Vulnerability from cvelistv5 โ€“ Published: 2026-09-10 08:22 โ€“ Updated: 2026-09-10 15:17
    VLAI
    Title
    GV-LPC2011/LPC2211 - ONVIF SetUser Stack-Frame Overflow Denial of Service
    Summary
    GeoVision GV-LPC2211 V1.13 copies an oversized ONVIF SetUser password into a fixed stack field, allowing an authenticated administrator to crash the ONVIF worker.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 15:15 UTC
    CWE
    • CWE-121 - Stack-based buffer overflow
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: V1.13
    Unaffected: V1.14
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:v1.13:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-10 05:35
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88280",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T15:15:34.880811Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:17:19.483Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "V1.13"
                },
                {
                  "status": "unaffected",
                  "version": "V1.14"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:v1.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:v1.14:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "datePublic": "2026-09-10T05:35:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.13 copies an oversized ONVIF SetUser password into a fixed stack field, allowing an authenticated administrator to crash the ONVIF worker."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.13 copies an oversized ONVIF SetUser password into a fixed stack field, allowing an authenticated administrator to crash the ONVIF worker."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 4.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121 Stack-based buffer overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:22:34.747Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GV-LPC2011/LPC2211 - ONVIF SetUser Stack-Frame Overflow Denial of Service",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88280",
        "datePublished": "2026-09-10T08:22:34.747Z",
        "dateReserved": "2026-09-10T02:56:04.082Z",
        "dateUpdated": "2026-09-10T15:17:19.483Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88279 (GCVE-0-2026-88279)

    Vulnerability from cvelistv5 โ€“ Published: 2026-09-10 08:22 โ€“ Updated: 2026-09-10 15:25
    VLAI
    Title
    GV-LPC2011/LPC2211 - ONVIF CreateUsers Username/Password Stack-Frame Overflow Denial of Service
    Summary
    GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers username or password values into fixed stack fields, allowing an authenticated administrator to crash the ONVIF worker.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 15:21 UTC
    CWE
    • CWE-121 - Stack-based buffer overflow
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.13
    Unaffected: 1.14
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-10 05:32
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88279",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T15:21:55.865736Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:25:30.611Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.13"
                },
                {
                  "status": "unaffected",
                  "version": "1.14"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "datePublic": "2026-09-10T05:32:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers username or password values into fixed stack fields, allowing an authenticated administrator to crash the ONVIF worker."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers username or password values into fixed stack fields, allowing an authenticated administrator to crash the ONVIF worker."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 4.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121 Stack-based buffer overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:22:12.621Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GV-LPC2011/LPC2211 - ONVIF CreateUsers Username/Password Stack-Frame Overflow Denial of Service",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88279",
        "datePublished": "2026-09-10T08:22:12.621Z",
        "dateReserved": "2026-09-10T02:56:04.082Z",
        "dateUpdated": "2026-09-10T15:25:30.611Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88275 (GCVE-0-2026-88275)

    Vulnerability from cvelistv5 โ€“ Published: 2026-09-10 08:20 โ€“ Updated: 2026-09-10 15:42
    VLAI
    Title
    GV-LPC2011/LPC2211 - Wireless WPA-PSK Command Injection
    Summary
    GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to execute arbitrary commands as root when wireless configuration is applied.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 15:40 UTC
    CWE
    • CWE-78 - Improper neutralization of special elements used in an OS command ('OS command injection')
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.13
    Unaffected: 1.14
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-10 03:48
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88275",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T15:40:29.885435Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:42:01.680Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.13"
                },
                {
                  "status": "unaffected",
                  "version": "1.14"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "datePublic": "2026-09-10T03:48:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to execute arbitrary commands as root when wireless configuration is applied."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to execute arbitrary commands as root when wireless configuration is applied."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-88",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-88 OS Command Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:20:58.135Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GV-LPC2011/LPC2211 - Wireless WPA-PSK Command Injection",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88275",
        "datePublished": "2026-09-10T08:20:58.135Z",
        "dateReserved": "2026-09-10T02:56:02.025Z",
        "dateUpdated": "2026-09-10T15:42:01.680Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88274 (GCVE-0-2026-88274)

    Vulnerability from cvelistv5 โ€“ Published: 2026-09-10 08:20 โ€“ Updated: 2026-09-10 15:49
    VLAI
    Title
    GV-LPC2011/LPC2211 - Wireless SSID Command Injection
    Summary
    GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless SSID containing shell syntax to execute arbitrary commands as root.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 15:47 UTC
    CWE
    • CWE-78 - Improper neutralization of special elements used in an OS command ('OS command injection')
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.13
    Unaffected: 1.14
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88274",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T15:47:12.392120Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:49:07.020Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.13"
                },
                {
                  "status": "unaffected",
                  "version": "1.14"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless SSID containing shell syntax to execute arbitrary commands as root."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless SSID containing shell syntax to execute arbitrary commands as root."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-88",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-88 OS Command Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:20:27.221Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GV-LPC2011/LPC2211 - Wireless SSID Command Injection",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88274",
        "datePublished": "2026-09-10T08:20:27.221Z",
        "dateReserved": "2026-09-10T02:56:02.025Z",
        "dateUpdated": "2026-09-10T15:49:07.020Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88273 (GCVE-0-2026-88273)

    Vulnerability from cvelistv5 โ€“ Published: 2026-09-10 08:20 โ€“ Updated: 2026-09-10 15:52
    VLAI
    Title
    GV-LPC2011/LPC2211 - PPPoE Username Shell-Configuration Command Injection
    Summary
    GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a sourced shell configuration assignment and execute arbitrary commands as root.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 15:52 UTC
    CWE
    • CWE-78 - Improper neutralization of special elements used in an OS command ('OS command injection')
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-LPC2011/LPC2211 Affected: 1.13
    Unaffected: 1.14
        cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-10 03:28
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88273",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T15:52:03.236073Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T15:52:25.823Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GV-LPC2011/LPC2211",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.13"
                },
                {
                  "status": "unaffected",
                  "version": "1.14"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University"
            }
          ],
          "datePublic": "2026-09-10T03:28:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a sourced shell configuration assignment and execute arbitrary commands as root."
                }
              ],
              "value": "GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a sourced shell configuration assignment and execute arbitrary commands as root."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-88",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-88 OS Command Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:20:07.306Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "GV-LPC2011/LPC2211 - PPPoE Username Shell-Configuration Command Injection",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-88273",
        "datePublished": "2026-09-10T08:20:07.306Z",
        "dateReserved": "2026-09-10T02:56:02.025Z",
        "dateUpdated": "2026-09-10T15:52:25.823Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }