Executive brief
GeoVision GV-LPC2211 is a network-attached camera system used in video surveillance deployments. The device fails to properly validate authentication tokens in ONVIF camera control operations, allowing an attacker who captures a legitimate user's authentication credentials to replay them indefinitely to control the camera. This enables persistent unauthorized access to critical surveillance infrastructure without requiring the original credentials.
Technical details
The vulnerability is a WS-Security UsernameToken replay attack in GeoVision GV-LPC2211 V1.13. The device fails to enforce freshness checks or nonce reuse protection on PasswordDigest tokens used in ONVIF web service operations. An attacker who captures a valid PasswordDigest token (e.g., via network sniffing or man-in-the-middle attack) can replay it to authenticate subsequent ONVIF commands without needing the actual password. The attack requires network access to the device's ONVIF interface, but does not require prior authentication. Patches or firmware updates are available through GeoVision's normal release cycle for supported products.
Affected products
- GeoVision GV-LPC2211 V1.13
Timeline
- 2026-09-10: disclosed