Executive brief
GeoVision license plate recognition cameras are affected by a critical security flaw that allows unauthorized individuals to take control of the device. By sending specially crafted login information over the network, an attacker can cause the system to crash or execute malicious commands. This could lead to a total loss of video surveillance, unauthorized access to sensitive camera feeds, or the device being used as a foothold to attack other parts of the corporate network.
Technical details
A stack-based buffer overflow vulnerability (CWE-121) exists in the 'vlsvr' service of GeoVision GV-LPC2011 and GV-LPC2211 license plate recognition cameras. The flaw is rooted in insufficient length validation when the service processes remote login data. A remote, unauthenticated attacker can exploit this by sending crafted login packets containing overly long input strings. Successful exploitation can lead to memory corruption, resulting in a denial of service (DoS) or arbitrary code execution with the privileges of the affected service. The vulnerability is addressed in firmware version 1.13.
Affected products
- GeoVision GV-LPC2011 V1.12 and earlier
- GeoVision GV-LPC2211 V1.12 and earlier
Timeline
- 2026-06-26: advisory: NVD publication date
- 2026-06-26: disclosed: CVE record published by GeoVision (CNA)
- 2026-06-26: patched: Firmware V1.13 released to address the issue