Executive brief
GeoVision GV-LPC2211 is a license plate recognition camera used in parking and traffic management systems. An unauthenticated remote attacker can exploit a flaw in the VLSVR protocol to declare excessively large frame sizes without providing data, causing the device to allocate memory indefinitely and exhaust connection and worker resources. This results in a denial of service condition, rendering the camera unavailable for legitimate surveillance operations.
Technical details
The vulnerability is a resource exhaustion flaw in the VLSVR protocol implementation on GeoVision GV-LPC2211 V1.14. An unauthenticated remote attacker can send VLSVR frames with unbounded length declarations without completing the transmission, causing the device to allocate memory and block worker threads indefinitely while waiting for frame data that never arrives. The flaw requires only network reachability to the device and no authentication. An attacker can exhaust memory, connection pools, and worker thread resources, leading to denial of service. A patch availability date is not specified in available advisories.
Affected products
- GeoVision GV-LPC2211 V1.14 (260903)
Timeline
- 2026-09-10: disclosed