Junglewise Threat Intelligence

CVE-2026-88283: GeoVision GV-LPC2211 buffer overflow in ONVIF CreateUsers

CVE-2026-88283 · Severity: medium · CVSS 4.9 · Published 2026-09-10

Technologies: Geovision Gv-Lpc2211. Vendors: Geovision.

Executive brief

The GeoVision GV-LPC2211 is a network camera device used for surveillance in commercial and institutional settings. An authenticated administrator can send a specially crafted ONVIF request with repeated User elements to cause a stack buffer overflow, crashing the camera's ONVIF service and disrupting video recording and monitoring capabilities.

Technical details

This vulnerability is a stack buffer overflow in the ONVIF CreateUsers request handler. The vulnerable component fails to properly validate and limit the number of repeated User elements in the request, allowing an attacker to write beyond allocated buffer boundaries. The attack requires authentication as an administrator on the device and network access to the ONVIF service port. Successful exploitation causes the ONVIF worker process to crash, resulting in denial of service of ONVIF-based management and user creation functions. A patch is expected in a future firmware release.

Affected products

  • GeoVision GV-LPC2211 V1.13

Timeline

  • 2026-09-10: disclosed

References

Related threats