ZeroHour

CVE-2026-88287

niche

Unauthenticated stack overflow DoS in GeoVision GV-LPC2211 ONVIF discovery

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-88287 is a stack-based buffer overflow (CWE-121) in the ONVIF WS-Discovery handler of the GeoVision GV-LPC2211 license-plate-capture camera running firmware V1.13, which does not bound the number of Scopes tokens accepted in a Probe request. A remote, unauthenticated attacker can trigger the flaw by sending a crafted WS-Discovery Probe containing an excessive number of Scopes tokens to the camera's discovery service, corrupting stack control state. The outcome is a crash of the discovery process, i.e. a denial of service; the CVSS vector (C:N/I:N/A:H) indicates no confidentiality or integrity impact. Affected organizations are those operating GV-LPC2211 cameras on firmware V1.13 whose ONVIF/WS-Discovery interface is reachable over the network. There is currently no public proof-of-concept, the issue is not in CISA KEV, and no in-the-wild exploitation has been reported.

What to do: Check the firmware version on any GV-LPC2211 units you operate and apply GeoVision's patched firmware when available (the current data does not specify a fixed version). As an interim mitigation, restrict access to the camera's ONVIF WS-Discovery service (typically UDP 3702) from untrusted networks using firewall or ACL rules. Impact is availability-only (crash of the discovery process), so prioritize patching where ONVIF discovery failures would disrupt video management or LPR integrations.

Affected
GeoVision GV-LPC2211 (license plate capture IP camera)V1.13 (other firmware versions not specified in the available data)
Estimated exposure
niche~1,000-10,000 exposed devices (single-model LPR camera, mostly deployed on closed parking/security LANs) — No public installed-base or internet-scan data exists for this specific camera model, so the estimate reflects the niche license-plate-capture camera segment and the fact that WS-Discovery is typically reachable only from local…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens in unauthenticated ONVIF WS-Discovery Probe requests, allowing a remote attacker to corrupt stack control state and crash the discovery process.

Weakness
CWE-121
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.