Executive brief
GeoVision license plate recognition cameras are affected by a critical security flaw that allows an unauthorized person to take control of the device over the network. By sending a specially crafted request, an attacker can crash the camera's software or execute malicious code, potentially leading to unauthorized surveillance or a foothold in the corporate network. This issue affects models GV-LPC2011 and GV-LPC2211 running firmware version 1.12 or older.
Technical details
A stack-based buffer overflow vulnerability (CWE-121) exists in the 'ssvr' service of GeoVision GV-LPC2011 and GV-LPC2211 devices. The flaw is rooted in insufficient bounds checking when the service parses RTSP Digest authentication fields. A remote, unauthenticated attacker can exploit this by sending a crafted RTSP request containing excessively long authentication data. Successful exploitation can lead to memory corruption, allowing for arbitrary code execution or a denial-of-service (DoS) condition. The vulnerability is addressed in firmware version 1.13.
Affected products
- GeoVision GV-LPC2011 V1.12 and earlier
- GeoVision GV-LPC2211 V1.12 and earlier
Timeline
- 2026-06-26: advisory: NVD publication date
- 2026-06-26: disclosed: CVE published by GeoVision (CNA)