Junglewise Threat Intelligence

CVE-2026-88286: GeoVision GV-LPC2211 PTZ connection state denial of service

CVE-2026-88286 · Severity: high · CVSS 7.5 · Published 2026-09-10

Technologies: Geovision Gv-Lpc2211. Vendors: Geovision.

Executive brief

The GeoVision GV-LPC2211 is an IP-based PTZ (Pan-Tilt-Zoom) camera used in video surveillance systems. A vulnerability in this device allows an unauthenticated attacker to remotely block the PTZ connection handler, preventing legitimate users from controlling camera movement and causing a denial of service to surveillance operations that depend on PTZ functionality.

Technical details

The GV-LPC2211 V1.13 improperly manages PTZ connection state, failing to validate or enforce authentication before accepting PTZ control connections. An unauthenticated remote client can establish a connection and leave it in a state that blocks the accept loop, preventing new legitimate PTZ connections from being processed. The vulnerability is network-accessible and requires no user interaction or prior authentication. An attacker can disrupt camera pan-tilt-zoom operations and deny PTZ functionality to authorized users. A patch is likely available through GeoVision's standard firmware update process.

Affected products

  • GeoVision GV-LPC2211 V1.13

Timeline

  • 2026-09-10: disclosed

References

Related threats