Junglewise Threat Intelligence

CVE-2026-88279: GeoVision GV-LPC2211 stack buffer overflow in ONVIF CreateUsers

CVE-2026-88279 · Severity: medium · CVSS 4.9 · Published 2026-09-10

Technologies: Geovision Gv-Lpc2211. Vendors: Geovision.

Executive brief

The GeoVision GV-LPC2211 is a license plate recognition camera used in traffic monitoring and access control systems. An authenticated administrator can exploit a buffer overflow vulnerability by sending oversized ONVIF credentials, causing the ONVIF service to crash and resulting in denial of service to legitimate users and systems relying on camera functionality.

Technical details

This is a stack buffer overflow vulnerability in the ONVIF CreateUsers handler of GeoVision GV-LPC2211 V1.13. The vulnerable component fails to properly validate the length of username or password fields before copying them into fixed-size stack buffers, allowing an authenticated administrator to overflow the buffer. The attack requires network reachability to the ONVIF interface and valid administrative credentials. A successful exploit crashes the ONVIF worker process, causing denial of service. A patch or firmware update is likely available through GeoVision's standard release process.

Affected products

  • GeoVision GV-LPC2211 V1.13

Timeline

  • 2026-09-10: disclosed

References

Related threats