Executive brief
GeoVision license plate recognition cameras are affected by a security flaw that allows an unauthenticated attacker to crash the device remotely. By sending a specially crafted web request, an attacker can trigger a system failure, leading to a total loss of camera availability and surveillance capabilities. This could disrupt security operations and monitoring at facilities using these specific camera models.
Technical details
A NULL pointer dereference vulnerability exists in the HTTP request parsing logic of multiple CGI components within GeoVision GV-LPC2011 and GV-LPC2211 firmware. The issue stems from improper validation of required HTTP request metadata before it is processed by the affected components. A remote, unauthenticated attacker can exploit this by sending a specially crafted HTTP request to the device. Successful exploitation causes the affected process to crash, resulting in a persistent denial of service (DoS) until the service or device is restarted. The vulnerability is addressed in firmware version 1.13.
Affected products
- GeoVision GV-LPC2011 v1.12 and earlier
- GeoVision GV-LPC2211 v1.12 and earlier
Timeline
- 2026-06-26: advisory: NVD publication date
- 2026-06-26: disclosed: CVE published by GeoVision (CNA)