Executive brief
GeoVision's GV-LPC2211 is a license plate recognition camera used in automated traffic monitoring and parking systems. A flaw in its ONVIF web service allows an authenticated administrator to send specially crafted delete-user requests that crash the device's network service, causing temporary unavailability of camera control and monitoring functions.
Technical details
The vulnerability is a stack buffer overflow in the ONVIF DeleteUsers request handler. The vulnerable component fails to validate or limit the number of repeated Username XML elements in incoming DeleteUsers requests. An authenticated administrator can exploit this by sending a request with an excessive number of Username elements, causing a stack array to overflow and crash the ONVIF worker process. No patches have been publicly announced at the time of advisory publication. The attack requires valid administrator credentials and network reachability to the ONVIF service port.
Affected products
- GeoVision GV-LPC2211 V1.13
Timeline
- 2026-09-10: disclosed