Geovision
Geovision Gv-lpc2211: vulnerabilidades y CVE
Geovision Gv-lpc2211 tiene 33 vulnerabilidades publicadas, 33 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE33
Últimos 12 meses33
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-88290 | Alta (7.5) | 0.46% | — | 10 sept 2026 | GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker… |
| CVE-2026-88289 | Alta (7.5) | 0.57% | — | 10 sept 2026 | GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote… |
| CVE-2026-88288 | Media (6.5) | 0.55% | — | 10 sept 2026 | GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a remote user with valid web credentials to read arbitrary files accessible to the root-run web service. |
| CVE-2026-88287 | Alta (7.5) | 0.55% | — | 10 sept 2026 | GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens in unauthenticated ONVIF WS-Discovery Probe requests, allowing a remote attacker to corrupt stack control state and crash the discovery process. |
| CVE-2026-88286 | Alta (7.5) | 0.46% | — | 10 sept 2026 | GeoVision GV-LPC2211 V1.13 improperly manages PTZ connection state, allowing an unauthenticated remote client to block the accept loop and prevent new PTZ connections. |
| CVE-2026-88285 | Crítica (9.4) | 0.51% | — | 10 sept 2026 | GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve PTZ information and issue PTZ or raw serial commands. |
| CVE-2026-88284 | Media (4.9) | 0.44% | — | 10 sept 2026 | GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF SetUser requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker. |
| CVE-2026-88283 | Media (4.9) | 0.44% | — | 10 sept 2026 | GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF CreateUsers requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker. |
| CVE-2026-88282 | Alta (7.2) | 0.54% | — | 10 sept 2026 | GeoVision GV-LPC2211 V1.13 allows an administrator-controlled FTP username containing shell metacharacters to be executed as arbitrary root commands during a subsequent FTP-account update. |
| CVE-2026-88281 | Media (4.9) | 0.44% | — | 10 sept 2026 | GeoVision GV-LPC2211 V1.13 fails to limit repeated Username elements in ONVIF DeleteUsers requests, allowing an authenticated administrator to overflow a stack array and crash the ONVIF worker. |
| CVE-2026-88280 | Media (4.9) | 0.44% | — | 10 sept 2026 | GeoVision GV-LPC2211 V1.13 copies an oversized ONVIF SetUser password into a fixed stack field, allowing an authenticated administrator to crash the ONVIF worker. |
| CVE-2026-88279 | Media (4.9) | 0.44% | — | 10 sept 2026 | GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers username or password values into fixed stack fields, allowing an authenticated administrator to crash the ONVIF worker. |
| CVE-2026-88278 | Crítica (9.8) | 0.48% | — | 10 sept 2026 | GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations. |
| CVE-2026-88277 | Alta (8.8) | 0.65% | — | 10 sept 2026 | GeoVision GV-LPC2211 V1.13 allows an authenticated ONVIF user to inject shell commands through ConsumerReference.Address and execute arbitrary commands as root. |
| CVE-2026-88276 | Alta (7.2) | 0.70% | — | 10 sept 2026 | GeoVision GV-LPC2211 V1.13 allows administrator-controlled WEP key values containing shell syntax to execute arbitrary commands as root. |
| CVE-2026-88275 | Alta (7.2) | 0.70% | — | 10 sept 2026 | GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to execute arbitrary commands as root when wireless configuration is applied. |
| CVE-2026-88274 | Alta (7.2) | 0.70% | — | 10 sept 2026 | GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless SSID containing shell syntax to execute arbitrary commands as root. |
| CVE-2026-88273 | Alta (7.2) | 0.70% | — | 10 sept 2026 | GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a sourced shell configuration assignment and execute arbitrary commands as root. |
| CVE-2026-88272 | Alta (7.2) | 0.54% | — | 10 sept 2026 | GeoVision GV-LPC2211 V1.13 allows an administrator-controlled username containing shell metacharacters to be executed as arbitrary root commands when the stored username is later deleted. |
| CVE-2026-88271 | Alta (8.8) | 0.42% | — | 10 sept 2026 | GeoVision GV-LPC2211 V1.13 allows a Guest user to overwrite device configuration and replace the administrator password through SSVR. |
| CVE-2026-88270 | Media (6.5) | 0.37% | — | 10 sept 2026 | GeoVision GV-LPC2211 V1.13 allows a Guest user to enter SSVR firmware-upgrade mode and disrupt live services before any firmware image is validated. |
| CVE-2026-88269 | Media (6.5) | 0.34% | — | 10 sept 2026 | GeoVision GV-LPC2211 V1.13 allows a Guest user to retrieve persistent device configuration containing plaintext administrative and user credentials through SSVR. |
| CVE-2026-88268 | Media (6.5) | 0.41% | — | 10 sept 2026 | GeoVision GV-LPC2211 V1.13 contains an authenticated stack buffer overflow in SSVR fragment reassembly that allows a valid user to crash the SSVR service. |
| CVE-2026-57881 | Crítica (9.8) | 0.65% | — | 26 jun 2026 | An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient length validation when processing remote… |
| CVE-2026-57880 | Crítica (9.8) | 0.95% | — | 26 jun 2026 | An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when parsing RTSP Digest… |
| CVE-2026-57879 | Crítica (9.8) | 0.95% | — | 26 jun 2026 | An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing RTSP… |
| CVE-2026-57878 | Crítica (9.8) | 0.95% | — | 26 jun 2026 | An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing web… |
| CVE-2026-57877 | Alta (8.6) | 0.43% | — | 26 jun 2026 | An unauthenticated format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper handling of externally controlled input during log message… |
| CVE-2026-57876 | Alta (7.5) | 0.55% | — | 26 jun 2026 | An unauthenticated out-of-bounds write vulnerability exists in onvif.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing HTTP request… |
| CVE-2026-57875 | Alta (7.5) | 0.73% | — | 26 jun 2026 | An unauthenticated NULL pointer dereference vulnerability exists in the HTTP request parsing logic of multiple CGI components in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.