Executive brief
A security vulnerability exists in certain GeoVision license plate recognition cameras. An unauthorized person could remotely crash the camera by sending a specially crafted file upload request, leading to a total loss of video monitoring and security operations. This could allow physical security breaches to go undetected while the device is offline.
Technical details
A classic buffer overflow (CWE-120) exists in the IEEE8021x_upload.cgi component of GeoVision GV-LPC2011 and GV-LPC2211 firmware. The vulnerability is rooted in insufficient bounds checking when parsing filename values within multipart upload data. A remote, unauthenticated attacker can exploit this by sending a crafted HTTP POST request containing an overly long filename string. This results in memory corruption and a subsequent denial of service (DoS) of the device. The issue is addressed in firmware version 1.13.
Affected products
- GeoVision GV-LPC2011 V1.12 and earlier
- GeoVision GV-LPC2211 V1.12 and earlier
Timeline
- 2026-06-26: advisory: NVD publication date
- 2026-06-26: disclosed: Initial disclosure by GeoVision