Junglewise Threat Intelligence

CVE-2026-88284: GeoVision GV-LPC2211 ONVIF SetUser denial of service

CVE-2026-88284 · Severity: medium · CVSS 4.9 · Published 2026-09-10

Technologies: Geovision Gv-Lpc2211. Vendors: Geovision.

Executive brief

GeoVision GV-LPC2211 is a license plate recognition camera with ONVIF network protocol support. An authenticated administrator can send malformed ONVIF SetUser requests with repeated User elements to crash the ONVIF worker process, disrupting the camera's network-based management and monitoring capabilities. Recovery requires manual intervention.

Technical details

The vulnerability is a denial-of-service flaw in the ONVIF SetUser request handler of GeoVision GV-LPC2211 V1.13. The vulnerable component fails to properly validate or limit the number of repeated User elements in incoming ONVIF SetUser requests, allowing an attacker with administrator credentials to overwrite stack control state through crafted input. An authenticated attacker can trigger a stack buffer overflow or memory corruption condition by sending a specially crafted request, crashing the ONVIF worker process. Attack requires valid administrator credentials and network reachability to the device's ONVIF interface. A firmware patch for V1.13 is available from GeoVision.

Affected products

  • GeoVision GV-LPC2211 V1.13

Timeline

  • 2026-09-10: disclosed

References

Related threats