VYPR
advisoryPublished Sep 10, 2026· Updated Sep 13, 2026· 1 source

Geovision GV-LPC2211: 23 Vulnerabilities Disclosed, Enabling RCE and DoS

Key findings • 23 CVEs disclosed on 2026-09-10 for Geovision GV-LPC2211, impacting V1.13 and V1.14. • Multiple vulnerabilities allow for remote code execution as root via various input manipu…

Key findings

  • 23 CVEs disclosed on 2026-09-10 for Geovision GV-LPC2211, impacting V1.13 and V1.14.
  • Multiple vulnerabilities allow for remote code execution as root via various input manipulations.
  • Critical and high-severity flaws enable denial-of-service, unauthorized access, and credential compromise.
  • ONVIF and VLSVR services are particularly affected by input validation and authentication issues.
  • Guest users can disrupt services, overwrite configurations, and retrieve sensitive credentials.

On September 10, 2026, a batch of 23 vulnerabilities was disclosed for the Geovision GV-LPC2211 product, affecting versions V1.13 and V1.14 (260903). These vulnerabilities, identified by CVE-2026-88268 through CVE-2026-88290, present a significant risk to users, with several critical and high-severity flaws allowing for remote code execution, denial-of-service conditions, and unauthorized access to sensitive information.

A prominent theme across these vulnerabilities is the improper handling of user inputs and network protocols, particularly within the ONVIF and VLSVR services. CVE-2026-88289 and CVE-2026-88288 highlight issues with unauthenticated clients exploiting VLSVR and ONVIF WS-Discovery requests, respectively, leading to memory exhaustion and service crashes. Similarly, CVE-2026-88284, CVE-2026-88283, and CVE-2026-88281 detail how authenticated administrators can crash the ONVIF worker service through malformed requests related to user management.

Remote code execution is a critical concern stemming from several vulnerabilities. CVE-2026-88282 and CVE-2026-88277 allow for arbitrary command execution as root through FTP username manipulation and ONVIF user injection, respectively. Additionally, CVE-2026-88276, CVE-2026-88275, and CVE-2026-88274 enable arbitrary command execution as root by exploiting WEP keys, WPA-PSK, and SSID values containing shell syntax. CVE-2026-88273 and CVE-2026-88272 also permit arbitrary command execution as root through PPPoE usernames and stored usernames with shell metacharacters.

The batch also includes vulnerabilities related to unauthorized access and information disclosure. CVE-2026-88285, a critical vulnerability, exposes an unauthenticated PTZ control service, allowing remote clients to issue PTZ and raw serial commands. CVE-2026-88271, a high-severity flaw, allows a Guest user to overwrite device configuration and change the administrator password. Furthermore, CVE-2026-88270 and CVE-2026-88269, both medium-severity, allow a Guest user to disrupt services by entering firmware-upgrade mode or retrieve sensitive configuration data, including plaintext credentials.

The affected versions are explicitly V1.13 and V1.14 (260903) of the Geovision GV-LPC2211. Users are strongly advised to update to patched versions as soon as possible to mitigate the risks associated with these numerous vulnerabilities. The coordinated disclosure of these 23 CVEs on a single day underscores the critical need for prompt security updates for the Geovision GV-LPC2211 to prevent potential exploitation.

This extensive disclosure highlights significant security weaknesses in the Geovision GV-LPC2211, particularly concerning input validation, authentication, and protocol handling. The presence of multiple remote code execution and denial-of-service vulnerabilities necessitates immediate attention from administrators managing these devices. Staying informed about vendor advisories and applying patches promptly is crucial for maintaining the security posture of these surveillance systems.

Synthesized by Vypr AI