CVE-2026-88271

8.8

GeoVision · GV-LPC2011/LPC2211

GeoVision GV-LPC2011 and GV-LPC2211 devices running version 1.13 are vulnerable to unauthorized configuration overwrites and administrative password replacement by guest users via the SSVR interface.

Executive summary

A critical vulnerability in GeoVision GV-LPC series cameras allows low-privileged guest users to gain full administrative control over the device, posing a severe risk of complete system compromise.

Vulnerability

This flaw stems from a missing authorization check (CWE-862) within the SSVR protocol, which permits an authenticated guest user to execute configuration changes and overwrite administrator credentials.

Business impact

Successful exploitation of this vulnerability allows an attacker to seize control of physical security infrastructure, potentially leading to unauthorized surveillance, disablement of security monitoring, or lateral movement within the network. With a CVSS score of 8.8, this high-severity flaw represents a significant risk to operational integrity and organizational security posture.

Remediation

Immediate Action: Update all affected GeoVision GV-LPC2011 and GV-LPC2211 units to firmware version 1.14 or later to address the authorization bypass.

Proactive Monitoring: Review device access logs for unusual configuration change events or unauthorized attempts to access the administrative management interface.

Compensating Controls: Restrict network access to the camera management interfaces by placing them on isolated VLANs and utilizing firewall rules to limit access to authorized administrative workstations only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for complete device takeover, administrators must prioritize the firmware update to version 1.14. If immediate patching is not feasible, ensure these devices are removed from public-facing networks and segmented to prevent exploitation by malicious guest users.

More GeoVision CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo o, per the CVE Program record.