ZeroHour

CVE-2026-88278

moderate

Replay authentication bypass in GeoVision GV-LPC2211 camera ONVIF interface

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

GeoVision GV-LPC2211 license-plate-capture cameras running firmware V1.13 do not enforce freshness or nonce-reuse checks on WS-Security UsernameToken credentials used for ONVIF requests. An attacker who can observe network traffic, for example by sniffing the camera's network segment, can capture a PasswordDigest token and replay it unchanged, and the camera will accept it for subsequent ONVIF operations. Because the replayed token is treated as valid, the attacker effectively authenticates as the ONVIF user without knowing the password, gaining access to ONVIF operations such as retrieving video streams and viewing or changing camera settings; the CVSS score reflects potentially high confidentiality and integrity impact, though the flaw is in authentication rather than code execution. Any deployment of the GV-LPC2211 on firmware V1.13 that uses WS-Security UsernameToken authentication over ONVIF is exposed, particularly where ONVIF traffic traverses a network an attacker can observe. As of now there are no public proofs of concept, the flaw is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported.

What to do: Upgrade the GV-LPC2211 to firmware newer than V1.13 as soon as GeoVision publishes a fix; the advisory names only V1.13, so administrators should check current firmware listings to confirm the fixed version. Until patched, restrict network access to the camera's ONVIF endpoint (management VLAN or firewall rules), use HTTPS for ONVIF traffic so captured digest tokens are harder to obtain, and monitor authentication logs for repeated logins using identical tokens or nonces, which indicates replay attempts.

Affected
GeoVision GV-LPC2211 license plate capture camera firmwareV1.13 (the only version named in the advisory; other versions are unconfirmed)
Estimated exposure
moderatelikely in the low thousands of affected systems at most worldwide; exact counts unknown — GV-LPC2211 is a single niche license-plate-capture camera model typically deployed in small per-site clusters (parking, gate, toll applications) rather than at fleet scale, and the available data provides no install counts or…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations.

Weakness
CWE-294
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.