Executive brief
The GeoVision GV-LPC2211 is an IP-based PTZ (Pan-Tilt-Zoom) camera used in video surveillance systems. A vulnerability in this device allows an unauthenticated attacker to remotely block the PTZ connection handler, preventing legitimate users from controlling camera movement and causing a denial of service to surveillance operations that depend on PTZ functionality.
Technical details
The GV-LPC2211 V1.13 improperly manages PTZ connection state, failing to validate or enforce authentication before accepting PTZ control connections. An unauthenticated remote client can establish a connection and leave it in a state that blocks the accept loop, preventing new legitimate PTZ connections from being processed. The vulnerability is network-accessible and requires no user interaction or prior authentication. An attacker can disrupt camera pan-tilt-zoom operations and deny PTZ functionality to authorized users. A patch is likely available through GeoVision's standard firmware update process.
Affected products
- GeoVision GV-LPC2211 V1.13
Timeline
- 2026-09-10: disclosed