Executive brief
A vulnerability in GeoVision license plate recognition cameras allows unauthorized individuals to bypass security controls and gain administrative access. The cameras use predictable session identifiers that can be guessed or discovered through automated trial-and-error. An attacker who successfully exploits this can take full control of the device's web management interface, potentially viewing camera feeds or altering security settings.
Technical details
A predictable session cookie vulnerability exists in the web interface of GeoVision LPC2011/LPC2211 firmware version 1.10. The root cause is the use of insufficient entropy in the Client ID generation functions (SIuUTIL_WebNewAdmId and SIuUTIL_WebNewGstId). Specifically, the pseudo-random number generator is seeded with the current system time and the resulting value is truncated to a range of only 100,000 possible values. Furthermore, the session validation function (SIuUTIL_WebLoginIsAdmin) fails to verify the remote IP address associated with the Client ID. A remote, unauthenticated attacker can use a series of HTTP requests to brute-force active session cookies and perform privileged operations.
Affected products
- GeoVision LPC2011 Firmware 1.10
- GeoVision LPC2211 Firmware 1.10
Timeline
- 2026-02-17: other: Initial vendor contact
- 2026-02-24: disclosed: Vendor disclosure
- 2026-04-14: patched: Vendor patch release
- 2026-05-04: advisory: NVD publication date
- 2026-06-15: other: Public release by Cisco Talos