CVE-2026-88271
nicheMissing Authorization in GeoVision GV-LPC2211 lets Guest users take over device config
CVE-2026-88271 is a missing-authorization flaw (CWE-862) in the SSVR interface of GeoVision's GV-LPC2211 license plate capture camera running firmware V1.13. A user with only Guest privileges can send requests to SSVR over the network, and the device fails to verify that the caller is authorized to make administrative changes. As a result, a Guest-level attacker can overwrite the device configuration and replace the administrator password, effectively taking over the camera (CVSS 3.1 score 8.8, High). Only deployments running the GV-LPC2211 on the cited firmware are affected; the advisory names no other GeoVision products or version ranges. There is currently no evidence of active exploitation: the flaw is not listed in CISA's KEV catalog and no public proof-of-concept is known.
What to do: Check the firmware version on any GV-LPC2211 cameras you operate (the advisory cites V1.13 as affected) and install updated firmware from GeoVision when it is released. As an interim mitigation, disable or restrict the Guest account on the device and limit access to its web/SSVR interface to trusted management networks. Also verify whether the administrator password or device configuration has been changed unexpectedly, which would indicate tampering.
| GeoVision GV-LPC2211 license plate capture camera (SSVR interface) | V1.13 (the only version cited in the advisory) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
GeoVision GV-LPC2211 V1.13 allows a Guest user to overwrite device configuration and replace the administrator password through SSVR.
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.