Executive brief
GeoVision GV-LPC2211 is a license plate recognition camera used in surveillance systems. The device fails to validate user-supplied input before writing it to fixed-size memory buffers, allowing an unauthenticated attacker on the network to crash the device's video server service, causing a denial of service to surveillance operations.
Technical details
The vulnerability is a classic stack buffer overflow in the VLSVR request handlers of GeoVision GV-LPC2211 V1.14 (build 260903). The affected component fails to validate the length of attacker-controlled variable-length fields before copying them into fixed-size stack buffers. The vulnerability is remotely exploitable without authentication via network requests to the VLSVR service. An attacker can craft a malicious request with an oversized field to trigger a stack buffer overflow, crashing the VLSVR service and causing denial of service. Patch availability has not been confirmed in the advisory.
Affected products
- GeoVision GV-LPC2211 V1.14 (260903)
Timeline
- 2026-09-10: disclosed