Executive brief
The GeoVision GV-LPC2211 is a license plate recognition camera used in traffic monitoring and access control systems. An authenticated administrator can exploit a buffer overflow vulnerability by sending oversized ONVIF credentials, causing the ONVIF service to crash and resulting in denial of service to legitimate users and systems relying on camera functionality.
Technical details
This is a stack buffer overflow vulnerability in the ONVIF CreateUsers handler of GeoVision GV-LPC2211 V1.13. The vulnerable component fails to properly validate the length of username or password fields before copying them into fixed-size stack buffers, allowing an authenticated administrator to overflow the buffer. The attack requires network reachability to the ONVIF interface and valid administrative credentials. A successful exploit crashes the ONVIF worker process, causing denial of service. A patch or firmware update is likely available through GeoVision's standard release process.
Affected products
- GeoVision GV-LPC2211 V1.13
Timeline
- 2026-09-10: disclosed