Junglewise Threat Intelligence

CVE-2026-88288: GeoVision GV-LPC2211 path traversal in BKDownloadLink.cgi

CVE-2026-88288 · Severity: medium · CVSS 6.5 · Published 2026-09-10

Technologies: Geovision Gv-Lpc2211. Vendors: Geovision.

Executive brief

The GeoVision GV-LPC2211 is a network-based access control or video surveillance device with a built-in web interface. An authenticated attacker can exploit a path traversal vulnerability in the BKDownloadLink.cgi script to read arbitrary files from the device's filesystem, potentially exposing sensitive configuration data, credentials, or system files that the web service can access. This impacts the confidentiality of data stored on or managed by the device.

Technical details

The vulnerability is a path traversal flaw in the BKDownloadLink.cgi endpoint that fails to properly validate or sanitize the filename parameter supplied by users. An attacker with valid web credentials can craft a request using directory traversal sequences (e.g., ../../../etc/passwd) to bypass intended file access restrictions and read files outside the intended download directory that are accessible to the root-privileged web service process. The attack requires network access and valid authentication credentials. GeoVision has published this as CVE-2026-88288 and patches are expected to be available through their standard firmware update channels.

Affected products

  • GeoVision GV-LPC2211 V1.13

Timeline

  • 2026-09-10: disclosed

References

Related threats