ZeroHour

CVE-2026-88286

Unauthenticated DoS in GeoVision GV-LPC2211 LPR camera PTZ connections

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

GeoVision GV-LPC2211 license plate capture camera firmware V1.13 improperly manages PTZ connection state, allowing an unauthenticated remote client to block the service's accept loop. An attacker who can reach the camera's PTZ service over the network can trigger this condition, after which new PTZ connections cannot be established. The result is a denial of service against PTZ control of the camera, consistent with the CVSS 7.5 score's availability-only impact (no confidentiality or integrity impact). Operators running GV-LPC2211 cameras on firmware V1.13, especially where the PTZ interface is reachable from untrusted networks, are affected. The flaw is not in CISA KEV, no public proof-of-concept is known, and no exploitation has been reported.

What to do: Update GV-LPC2211 firmware to a release newer than V1.13 once GeoVision publishes a fixed version. Until then, restrict access to the camera's PTZ service using firewall/ACL rules so only trusted management hosts can connect, and verify whether any deployed V1.13 cameras expose the PTZ interface to untrusted networks or the internet.

Affected
GeoVision GV-LPC2211 license plate capture camera firmwareV1.13 (no broader affected range specified in available data)
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

GeoVision GV-LPC2211 V1.13 improperly manages PTZ connection state, allowing an unauthenticated remote client to block the accept loop and prevent new PTZ connections.

Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.