CVE-2026-88278
9.8GeoVision · GV-LPCLPC2011/2211
GeoVision GV-LPC2211 V1.13 is vulnerable to authentication bypass via capture and replay of WS-Security PasswordDigest tokens due to missing nonce and freshness enforcement.
Executive summary
A critical authentication bypass vulnerability in GeoVision GV-LPCLPC2011/2211 allows unauthenticated attackers to hijack sessions through replay attacks.
Vulnerability
This is a capture-replay flaw (CWE-294) occurring within the WS-Security implementation. An unauthenticated attacker can capture a valid PasswordDigest token and reuse it to perform authorized ONVIF operations against the device.
Business impact
Successful exploitation of this vulnerability results in full unauthorized access to the affected surveillance equipment. Given the CVSS score of 9.8, this flaw poses a critical risk, as it allows attackers to manipulate device settings, access video feeds, or potentially pivot into the internal network. The lack of authentication requirements means the attack vector is trivial for any actor with network visibility to the device.
Remediation
Immediate Action: Update the GeoVision GV-LPCLPC2011/2211 firmware to version 1.14 or later to resolve the replay protection flaw.
Proactive Monitoring: Review system access logs for anomalous ONVIF command execution or repeated login attempts originating from unauthorized IP addresses.
Compensating Controls: Isolate affected cameras on a dedicated VLAN and restrict access to the ONVIF management interface using network-level firewalls.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a severe security failure in the device authentication process. Organizations using these GeoVision units must prioritize the firmware update to version 1.14 immediately to prevent unauthorized device control and potential surveillance data compromise.
More GeoVision CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section
Sources
Originally found and disclosed by Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo o, per the CVE Program record.