Junglewise Threat Intelligence

CVE-2026-88290: GeoVision GV-LPC2211 unbounded frame length denial of service

CVE-2026-88290 · Severity: high · CVSS 7.5 · Published 2026-09-10

Technologies: Geovision Gv-Lpc2211. Vendors: Geovision.

Executive brief

GeoVision GV-LPC2211 is a license plate recognition camera used in parking and traffic management systems. An unauthenticated remote attacker can exploit a flaw in the VLSVR protocol to declare excessively large frame sizes without providing data, causing the device to allocate memory indefinitely and exhaust connection and worker resources. This results in a denial of service condition, rendering the camera unavailable for legitimate surveillance operations.

Technical details

The vulnerability is a resource exhaustion flaw in the VLSVR protocol implementation on GeoVision GV-LPC2211 V1.14. An unauthenticated remote attacker can send VLSVR frames with unbounded length declarations without completing the transmission, causing the device to allocate memory and block worker threads indefinitely while waiting for frame data that never arrives. The flaw requires only network reachability to the device and no authentication. An attacker can exhaust memory, connection pools, and worker thread resources, leading to denial of service. A patch availability date is not specified in available advisories.

Affected products

  • GeoVision GV-LPC2211 V1.14 (260903)

Timeline

  • 2026-09-10: disclosed

References

Related threats