Executive brief
GeoVision license plate recognition cameras are affected by a security flaw that allows an unauthenticated attacker to crash the device remotely. By sending a specially crafted web request to the camera's certificate upload component, an attacker can trigger a system failure, leading to a total loss of availability for surveillance and monitoring operations. This could be used to disable security cameras before or during a physical security breach.
Technical details
An unauthenticated NULL pointer dereference vulnerability exists in the IEEE8021x_upload.cgi component of GeoVision GV-LPC2011 and GV-LPC2211 cameras. The issue stems from improper validation of multipart upload headers when the CGI process handles certificate-related upload fields. A remote, unauthenticated attacker can exploit this by sending a malformed multipart request, causing the CGI process to crash. This results in a denial of service (DoS) condition for the camera's web management and potentially its core functions. The vulnerability is addressed in firmware version 1.13.
Affected products
- GeoVision GV-LPC2011 1.12 and earlier
- GeoVision GV-LPC2211 1.12 and earlier
Timeline
- 2026-06-26: disclosed
- 2026-06-26: advisory
- 2026-06-26: patched: Fixed in version 1.13