CVE-2026-7371
7.4GeoVision Inc. · GV-LPC2011/LPC2211
Multiple reflected cross-site scripting vulnerabilities in GeoVision GV-LPC2011/LPC2211 allow attackers to execute arbitrary JavaScript code via crafted URLs.
Executive summary
Multiple reflected cross-site scripting vulnerabilities in the Web Interface of GeoVision GV-LPC2011/LPC2211 devices allow unauthenticated attackers to execute arbitrary JavaScript code.
Vulnerability
This flaw is classified as a cross-site scripting vulnerability under CWE-79, triggered via the ssi.cgi functionality and error messages when requesting non-existing pages, requiring unauthenticated user interaction.
Business impact
A successful exploit allows malicious actors to execute arbitrary JavaScript within the context of a victim session, potentially leading to session hijacking, credential theft, or unauthorized actions performed on behalf of the user. With a CVSS score of 7.4, this high severity rating reflects significant risk to web interface confidentiality and integrity.
Remediation
Immediate Action: Update the firmware to version V1.12-260330 or later as provided by the vendor.
Proactive Monitoring: Monitor web server access logs for anomalous URL parameters containing script tags or suspicious error page requests.
Compensating Controls: Deploy a Web Application Firewall to detect and block reflected cross-site scripting payloads targeting the device interface.
Exploitation status
Public Exploit Available: No (there is no confirmed public exploit in the available data).
Analyst recommendation
Given the high severity score and potential for user session compromise, administrators should apply the latest vendor firmware update immediately. Ensure that network access to device management interfaces is strictly restricted to trusted internal networks to minimize exposure.
More GeoVision Inc. CVEs
Sources
Originally found and disclosed by Philippe Laulheret of Cisco Talos., with Kelly Patterson of Cisco Talos. (remediation reviewer), Martin Zeiser of Cisco Talos. (coordinator), per the CVE Program record.