Junglewise Threat Intelligence

CVE-2026-42368: GeoVision LPC2011/LPC2211 privilege escalation in web interface

CVE-2026-42368 · Severity: critical · CVSS 9.9 · Published 2026-05-04

Technologies: Geovision Gv-Lpc2011 Firmware, Geovision Gv-Lpc2211 Firmware, Geovision Gv-Lpc2211, Geovision LPC2011 Firmware, Geovision LPC2211 Firmware, Geovision Gv-Lpc2011. Vendors: Geovision.

Executive brief

A privilege escalation vulnerability exists in the web interface of GeoVision LPC2011 and LPC2211 license plate recognition cameras. These devices are used for automated vehicle identification and security monitoring. An attacker with low-level guest access can exploit this flaw to perform administrative actions, such as rebooting the device, modifying system settings, or stealing administrator credentials, potentially leading to a full takeover of the camera system.

Technical details

A privilege escalation vulnerability exists in the web interface of GeoVision LPC2011 and LPC2211 firmware version 1.10 due to incorrect privilege assignment (CWE-266). The root cause is a failure in the '/geo-cgi/' path handlers to verify user authorization levels; the system only checks for a valid session cookie without distinguishing between Guest and Administrator roles. A remote attacker with low-privileged 'Guest' credentials can send specially crafted HTTP requests to sensitive endpoints like 'geo-cgi/params.cgi' to retrieve the system shadow file or export the full configuration containing plaintext credentials. This allows for full administrative takeover, firmware tampering, or device disruption. A patch was released by the vendor in April 2026.

Affected products

  • GeoVision LPC2011 Firmware 1.10
  • GeoVision LPC2211 Firmware 1.10

Timeline

  • 2026-02-17: other: Initial vendor contact
  • 2026-02-24: disclosed: Vendor disclosure
  • 2026-04-14: patched: Vendor patch release
  • 2026-05-04: advisory: NVD publication date
  • 2026-06-15: disclosed: Public release by Cisco Talos

References

Related threats