Junglewise Threat Intelligence

CVE-2026-88271: GeoVision GV-LPC2211 privilege escalation in SSVR

CVE-2026-88271 · Severity: high · CVSS 8.8 · Published 2026-09-10

Technologies: Geovision Gv-Lpc2211. Vendors: Geovision.

Executive brief

The GeoVision GV-LPC2211 is a network surveillance device used in security monitoring systems. A vulnerability allows guest users to bypass access controls and overwrite the device's configuration, including the administrator password, gaining full control of the system. This could enable an attacker to monitor, modify, or disable surveillance without authorization.

Technical details

The vulnerability is a privilege escalation flaw in the SSVR (GeoVision's video server protocol/interface) component of the GV-LPC2211 V1.13. A guest user with minimal permissions can craft requests to overwrite device configuration settings and modify the administrator password. No authentication bypass is required beyond guest-level access, which may be available by default or easily obtained. An attacker can achieve complete control of the device, including access to video streams, configuration modification, and potential lateral movement within a network. Patch availability status is unknown from the advisory text.

Affected products

  • GeoVision GV-LPC2211 V1.13

Timeline

  • 2026-09-10: disclosed: CVE-2026-88271 published

References

Related threats