Junglewise Threat Intelligence

CVE-2026-88280: GeoVision GV-LPC2211 stack buffer overflow in ONVIF SetUser

CVE-2026-88280 · Severity: medium · CVSS 4.9 · Published 2026-09-10

Technologies: Geovision Gv-Lpc2211. Vendors: Geovision.

Executive brief

GeoVision GV-LPC2211 is a license plate recognition camera used for traffic monitoring and access control. A flaw in its ONVIF interface allows an authenticated administrator to send an oversized password that crashes the camera's ONVIF service, causing denial of service to surveillance monitoring and access control systems.

Technical details

This is a stack buffer overflow vulnerability in the GV-LPC2211 V1.13 firmware. The ONVIF SetUser function fails to properly validate the length of password input before copying it into a fixed-size stack buffer, allowing an authenticated administrator to trigger a buffer overflow. The vulnerability requires valid administrator credentials and network access to the ONVIF service (port 8080 or similar). Successful exploitation crashes the ONVIF worker process, causing denial of service to remote monitoring and configuration. No remote code execution is possible due to stack protections and the authentication requirement. A patched firmware version should be available from GeoVision.

Affected products

  • GeoVision GV-LPC2211 V1.13

Timeline

  • 2026-09-10: disclosed

References

Related threats