CVE-2026-88285
9.4GeoVision · GV-LPC2011/LPC2211
A missing authentication vulnerability in GeoVision GV-LPC2011 and GV-LPC2211 cameras allows unauthenticated remote attackers to control PTZ functionality and execute raw serial commands.
Executive summary
A critical authentication bypass vulnerability in GeoVision camera firmware permits unauthenticated remote attackers to manipulate device controls and execute arbitrary serial commands.
Vulnerability
The device exposes a PTZ control service that lacks authentication, allowing any unauthenticated network user to interact with sensitive device functions. This flaw involves the improper implementation of access controls for critical hardware management operations.
Business impact
The ability for an unauthorized party to manipulate physical security hardware poses a severe operational risk. An attacker could rotate cameras to blind surveillance, issue disruptive serial commands to impact hardware integrity, or use the device as a pivot point for further network compromise. With a CVSS score of 9.4, this vulnerability represents a critical threat to the confidentiality, integrity, and availability of the physical security environment.
Remediation
Immediate Action: Update the firmware on all affected GeoVision GV-LPC2011 and GV-LPC2211 units to version 1.14 or later to resolve the missing authentication flaw.
Proactive Monitoring: Review firewall logs for unusual traffic directed at the camera management interfaces and monitor audit logs for unauthorized PTZ control commands.
Compensating Controls: Restrict network access to the management ports of these devices using an isolated VLAN and implement a Web Application Firewall or proxy to enforce authentication before requests reach the device control service.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical nature of this vulnerability and the potential for direct physical impact, immediate action is required. Organizations should prioritize updating all vulnerable GeoVision cameras to the manufacturer-provided fixed version. If an immediate update is not feasible, ensure that these devices are not accessible from the public internet and limit administrative access to trusted management subnets until the patch is applied.
More GeoVision CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section
Sources
Originally found and disclosed by Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo o, per the CVE Program record.