Executive brief
GeoVision GV-LPC2211 network cameras expose a Pan-Tilt-Zoom (PTZ) control service on the network without requiring authentication. This allows attackers on the network to remotely control the camera's movement and retrieve sensitive information about the device, potentially compromising surveillance operations and enabling reconnaissance of physical spaces.
Technical details
The GV-LPC2211 V1.13 exposes a network-accessible PTZ service that fails to implement authentication controls, allowing unauthenticated remote clients to issue PTZ (pan, tilt, zoom) commands and retrieve PTZ configuration information. The vulnerability permits attackers to send raw serial commands in addition to standard PTZ operations. The attack vector is network-based with no authentication required, affecting any device connected to a reachable network segment. An attacker can manipulate camera positioning and potentially gather information about camera capabilities and configuration. Patching information should be obtained from GeoVision's security advisories.
Affected products
- GeoVision GV-LPC2211 V1.13
Timeline
- 2026-09-10: disclosed