Executive brief
GeoVision license plate recognition cameras are affected by a security flaw that allows unauthorized individuals to access internal system files. By sending a specially crafted web request, an attacker can bypass security restrictions to read sensitive information stored on the device. This could lead to the exposure of configuration data or other private files, potentially compromising the security of the surveillance network.
Technical details
A directory traversal vulnerability exists in the get_fcont.cgi component of GeoVision GV-LPC2011 and GV-LPC2211 firmware versions V1.12 and earlier. The issue stems from insufficient validation of user-supplied file path input before the CGI component accesses the requested file. An unauthenticated remote attacker can exploit this by sending a crafted HTTP request containing path traversal sequences (e.g., ../) to read arbitrary files accessible to the web server process. This vulnerability is addressed in firmware version V1.13.
Affected products
- GeoVision GV-LPC2011 V1.12 and earlier
- GeoVision GV-LPC2211 V1.12 and earlier
Timeline
- 2026-06-26: disclosed
- 2026-06-26: advisory
- 2026-06-26: patched: Fixed in version 1.13