CVE-2026-88287
nicheUnauthenticated stack overflow DoS in GeoVision GV-LPC2211 ONVIF discovery
CVE-2026-88287 is a stack-based buffer overflow (CWE-121) in the ONVIF WS-Discovery handler of the GeoVision GV-LPC2211 license-plate-capture camera running firmware V1.13, which does not bound the number of Scopes tokens accepted in a Probe request. A remote, unauthenticated attacker can trigger the flaw by sending a crafted WS-Discovery Probe containing an excessive number of Scopes tokens to the camera's discovery service, corrupting stack control state. The outcome is a crash of the discovery process, i.e. a denial of service; the CVSS vector (C:N/I:N/A:H) indicates no confidentiality or integrity impact. Affected organizations are those operating GV-LPC2211 cameras on firmware V1.13 whose ONVIF/WS-Discovery interface is reachable over the network. There is currently no public proof-of-concept, the issue is not in CISA KEV, and no in-the-wild exploitation has been reported.
What to do: Check the firmware version on any GV-LPC2211 units you operate and apply GeoVision's patched firmware when available (the current data does not specify a fixed version). As an interim mitigation, restrict access to the camera's ONVIF WS-Discovery service (typically UDP 3702) from untrusted networks using firewall or ACL rules. Impact is availability-only (crash of the discovery process), so prioritize patching where ONVIF discovery failures would disrupt video management or LPR integrations.
| GeoVision GV-LPC2211 (license plate capture IP camera) | V1.13 (other firmware versions not specified in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens in unauthenticated ONVIF WS-Discovery Probe requests, allowing a remote attacker to corrupt stack control state and crash the discovery process.
- Weakness
- CWE-121
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.