ZeroHour

CVE-2026-88271

niche

Missing Authorization in GeoVision GV-LPC2211 lets Guest users take over device config

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-88271 is a missing-authorization flaw (CWE-862) in the SSVR interface of GeoVision's GV-LPC2211 license plate capture camera running firmware V1.13. A user with only Guest privileges can send requests to SSVR over the network, and the device fails to verify that the caller is authorized to make administrative changes. As a result, a Guest-level attacker can overwrite the device configuration and replace the administrator password, effectively taking over the camera (CVSS 3.1 score 8.8, High). Only deployments running the GV-LPC2211 on the cited firmware are affected; the advisory names no other GeoVision products or version ranges. There is currently no evidence of active exploitation: the flaw is not listed in CISA's KEV catalog and no public proof-of-concept is known.

What to do: Check the firmware version on any GV-LPC2211 cameras you operate (the advisory cites V1.13 as affected) and install updated firmware from GeoVision when it is released. As an interim mitigation, disable or restrict the Guest account on the device and limit access to its web/SSVR interface to trusted management networks. Also verify whether the administrator password or device configuration has been changed unexpectedly, which would indicate tampering.

Affected
GeoVision GV-LPC2211 license plate capture camera (SSVR interface)V1.13 (the only version cited in the advisory)
Estimated exposure
nicheunknown; plausibly on the order of thousands of units, concentrated in parking and vehicle-gate deployments — No public install-base or internet-scan counts exist for this model, but the GV-LPC2211 is a single specialty license-plate-recognition camera in GeoVision's LPR line, typically deployed at parking lots and access-control gates rather than…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

GeoVision GV-LPC2211 V1.13 allows a Guest user to overwrite device configuration and replace the administrator password through SSVR.

Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.