Junglewise Threat Intelligence

CVE-2026-88270: GeoVision GV-LPC2211 firmware upgrade mode bypass

CVE-2026-88270 · Severity: medium · CVSS 6.5 · Published 2026-09-10

Technologies: Geovision Gv-Lpc2211. Vendors: Geovision.

Executive brief

GeoVision GV-LPC2211 is a license plate recognition camera used in surveillance and traffic enforcement systems. A vulnerability allows unauthenticated guest users to trigger firmware upgrade mode without proper validation, potentially disrupting live video monitoring services until the device is rebooted or properly configured.

Technical details

The vulnerability is an authentication bypass allowing guest users to enter SSVR (firmware upgrade) mode without proper authorization. The root cause is insufficient access control on the firmware upgrade interface—guest credentials can trigger upgrade mode initiation before firmware image validation occurs. Attack vector is network-based and requires no special privileges beyond guest access. An attacker can disrupt service availability by entering upgrade mode, though actual firmware corruption requires additional steps. The vulnerability affects GeoVision GV-LPC2211 V1.13; patches should be available from GeoVision's firmware download page.

Affected products

  • GeoVision GV-LPC2211 V1.13

Timeline

  • 2026-09-10: disclosed

References

Related threats