Executive brief
GeoVision license plate recognition cameras contain a critical security flaw in their web server component. An attacker can exploit this vulnerability over the network without needing a password to crash the device or potentially take full control of the camera. This could lead to a complete loss of video surveillance, unauthorized access to sensitive visual data, or the device being used as a foothold to attack other parts of the corporate network.
Technical details
A stack-based buffer overflow vulnerability (CWE-121) exists in the thttpd web server component of GeoVision GV-LPC2011 and GV-LPC2211 license plate recognition cameras. The flaw is rooted in insufficient bounds checking when processing web request parameters at a specific request path. A remote, unauthenticated attacker can exploit this by sending a specially crafted HTTP request containing overly long input strings. Successful exploitation can lead to memory corruption, resulting in a denial-of-service (DoS) condition or arbitrary code execution with the privileges of the web server. The vulnerability is addressed in firmware version 1.13.
Affected products
- GeoVision GV-LPC2011 V1.12 and earlier
- GeoVision GV-LPC2211 V1.12 and earlier
Timeline
- 2026-06-26: advisory: NVD publication date
- 2026-06-26: disclosed: CVE record published by GeoVision (CNA)