CVE-2026-42366

7.4

GeoVision · GV-LPC2011/LPC2211

Multiple reflected cross-site scripting vulnerabilities in the web interface of GeoVision GV-LPC2011 and GV-LPC2211 allow arbitrary JavaScript execution via crafted URLs.

Executive summary

A reflected cross-site scripting vulnerability in GeoVision GV-LPC2011 and GV-LPC2211 devices allows remote attackers to execute arbitrary JavaScript in victim browsers via crafted URLs, presenting a high risk of session hijacking and unauthorized administrative actions.

Vulnerability

This vulnerability involves CWE-79, improper neutralization of input during web page generation, affecting the ssi.cgi functionality within the web interface. Unauthenticated attackers require user interaction to trigger the flaw.

Business impact

A successful exploitation of these reflected cross-site scripting vulnerabilities can allow malicious actors to compromise user sessions, steal session cookies, or perform unauthorized actions on behalf of authenticated administrators. This undermines the confidentiality of user interactions with the device management interface. The CVSS score of 7.4 reflects a high severity risk due to the potential for impactful browser-based attacks over a network vector.

Remediation

Immediate Action: Update the firmware of affected GeoVision GV-LPC2011 and GV-LPC2211 devices to version V1.12-260330 or later, as provided by the vendor.

Proactive Monitoring: Monitor network and web server access logs for anomalous URL parameters containing script tags or encoded JavaScript directed at the ssi.cgi endpoint.

Compensating Controls: Deploy a Web Application Firewall to inspect incoming HTTP requests and block URLs containing malicious script payloads targeting the vulnerable web interface.

Exploitation status

Public Exploit Available: No - As of May 5, 2026, there is no confirmed public exploit in the available data.

Analyst recommendation

Administrators must prioritize updating vulnerable GeoVision devices to the latest firmware release to neutralize the cross-site scripting vector. Prompt remediation is critical to prevent potential session compromise and unauthorized administrative access stemming from crafted URLs.

More GeoVision CVEs

Sources

Originally found and disclosed by Philippe Laulheret of Cisco Talos., with Kelly Patterson of Cisco Talos. (remediation reviewer), Martin Zeiser of Cisco Talos. (coordinator), per the CVE Program record.