Geovision GV-LPC2211: 23 Vulnerabilities Disclosed, Enabling RCE and DoS
Geovision GV-LPC2211 faces a severe security event with 23 vulnerabilities disclosed, including remote code execution and denial-of-service flaws.

Key findings
- 23 CVEs disclosed on 2026-09-10 for Geovision GV-LPC2211, impacting V1.13 and V1.14.
- Multiple vulnerabilities allow for remote code execution as root via various input manipulations.
- Critical and high-severity flaws enable denial-of-service, unauthorized access, and credential compromise.
- ONVIF and VLSVR services are particularly affected by input validation and authentication issues.
- Guest users can disrupt services, overwrite configurations, and retrieve sensitive credentials.
On September 10, 2026, a batch of 23 vulnerabilities was disclosed for the Geovision GV-LPC2211 product, affecting versions V1.13 and V1.14 (260903). These vulnerabilities, identified by CVE-2026-88268 through CVE-2026-88290, present a significant risk to users, with several critical and high-severity flaws allowing for remote code execution, denial-of-service conditions, and unauthorized access to sensitive information.
A prominent theme across these vulnerabilities is the improper handling of user inputs and network protocols, particularly within the ONVIF and VLSVR services. CVE-2026-88289 and CVE-2026-88288 highlight issues with unauthenticated clients exploiting VLSVR and ONVIF WS-Discovery requests, respectively, leading to memory exhaustion and service crashes. Similarly, CVE-2026-88284, CVE-2026-88283, and CVE-2026-88281 detail how authenticated administrators can crash the ONVIF worker service through malformed requests related to user management.
Remote code execution is a critical concern stemming from several vulnerabilities. CVE-2026-88282 and CVE-2026-88277 allow for arbitrary command execution as root through FTP username manipulation and ONVIF user injection, respectively. Additionally, CVE-2026-88276, CVE-2026-88275, and CVE-2026-88274 enable arbitrary command execution as root by exploiting WEP keys, WPA-PSK, and SSID values containing shell syntax. CVE-2026-88273 and CVE-2026-88272 also permit arbitrary command execution as root through PPPoE usernames and stored usernames with shell metacharacters.
The batch also includes vulnerabilities related to unauthorized access and information disclosure. CVE-2026-88285, a critical vulnerability, exposes an unauthenticated PTZ control service, allowing remote clients to issue PTZ and raw serial commands. CVE-2026-88271, a high-severity flaw, allows a Guest user to overwrite device configuration and change the administrator password. Furthermore, CVE-2026-88270 and CVE-2026-88269, both medium-severity, allow a Guest user to disrupt services by entering firmware-upgrade mode or retrieve sensitive configuration data, including plaintext credentials.
The affected versions are explicitly V1.13 and V1.14 (260903) of the Geovision GV-LPC2211. Users are strongly advised to update to patched versions as soon as possible to mitigate the risks associated with these numerous vulnerabilities. The coordinated disclosure of these 23 CVEs on a single day underscores the critical need for prompt security updates for the Geovision GV-LPC2211 to prevent potential exploitation.
This extensive disclosure highlights significant security weaknesses in the Geovision GV-LPC2211, particularly concerning input validation, authentication, and protocol handling. The presence of multiple remote code execution and denial-of-service vulnerabilities necessitates immediate attention from administrators managing these devices. Staying informed about vendor advisories and applying patches promptly is crucial for maintaining the security posture of these surveillance systems.