Executive brief
GeoVision GV-LPC2211 is an IP camera used in video surveillance systems. A vulnerability allows guest users to retrieve the device's persistent configuration file, which contains administrative and user passwords stored in plaintext. An attacker with guest access can obtain these credentials and use them to gain full administrative control over the camera and potentially the broader surveillance network.
Technical details
The vulnerability is an information disclosure issue affecting GeoVision GV-LPC2211 version 1.13. A guest user can retrieve persistent device configuration data through the SSVR (GeoVision's proprietary protocol) without proper authorization controls. The configuration file contains plaintext credentials for administrative and user accounts. An attacker with network access and guest-level privileges can exploit this to extract sensitive credentials and escalate to full administrative control. A patch is expected in future firmware releases via GeoVision's product download page.
Affected products
- GeoVision GV-LPC2211 V1.13
Timeline
- 2026-09-10: disclosed