Junglewise Threat Intelligence

CVE-2026-88285: GeoVision GV-LPC2211 unauthenticated PTZ control service access

CVE-2026-88285 · Severity: critical · CVSS 9.4 · Published 2026-09-10

Technologies: Geovision Gv-Lpc2211. Vendors: Geovision.

Executive brief

GeoVision GV-LPC2211 network cameras expose a Pan-Tilt-Zoom (PTZ) control service on the network without requiring authentication. This allows attackers on the network to remotely control the camera's movement and retrieve sensitive information about the device, potentially compromising surveillance operations and enabling reconnaissance of physical spaces.

Technical details

The GV-LPC2211 V1.13 exposes a network-accessible PTZ service that fails to implement authentication controls, allowing unauthenticated remote clients to issue PTZ (pan, tilt, zoom) commands and retrieve PTZ configuration information. The vulnerability permits attackers to send raw serial commands in addition to standard PTZ operations. The attack vector is network-based with no authentication required, affecting any device connected to a reachable network segment. An attacker can manipulate camera positioning and potentially gather information about camera capabilities and configuration. Patching information should be obtained from GeoVision's security advisories.

Affected products

  • GeoVision GV-LPC2211 V1.13

Timeline

  • 2026-09-10: disclosed

References

Related threats