VYPR

LPC2011/LPC2211

by Geovision

CVEs (6)

  • CVE-2026-42368CriMay 4, 2026
    risk 0.64cvss 9.9epss 0.00

    A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to execute priviledged operation. An attacker can visit a webpage to trigger this vulnerability.

  • CVE-2026-42364CriMay 4, 2026
    risk 0.64cvss 9.9epss 0.00

    An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An attacker can modify a configuration value to trigger this vulnerability.

  • CVE-2026-42365HigMay 4, 2026
    risk 0.56cvss 8.6epss 0.00

    A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. An attacker can bruteforce session cookies to trigger this vulnerability.

  • CVE-2026-7371HigMay 4, 2026
    risk 0.48cvss 7.4epss 0.00

    Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. Reflected XXS via the error message for requesting non-existing page.

  • CVE-2026-42366HigMay 4, 2026
    risk 0.48cvss 7.4epss 0.00

    Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.

  • CVE-2026-42367MedMay 4, 2026
    risk 0.42cvss 6.5epss 0.00

    A privilege escalation vulnerability exists in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to credentials leak. An attacker can visit a webpage to trigger this vulnerability.