CVE-2026-88289
nicheUnauthenticated stack buffer overflow DoS in GeoVision GV-LPC2211 VLSVR service
GeoVision GV-LPC2211 firmware version V1.14 (260903) contains stack-based buffer overflows (CWE-121) in multiple VLSVR request handlers, which copy attacker-controlled variable-length fields into fixed-size stack buffers without validating their length. An unauthenticated remote attacker who sends crafted requests containing oversized fields to these handlers can overflow the stack buffers and crash the VLSVR service. The CVSS impact metrics (C:N/I:N/A:H) indicate availability impact only, so remote code execution or data compromise is not claimed in the available data. Affected users are operators of GeoVision GV-LPC2211 license plate recognition cameras running the named firmware version. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the flaw is not currently listed in CISA's Known Exploited Vulnerabilities catalog.
What to do: Owners of GV-LPC2211 cameras should check their firmware version and plan an upgrade from V1.14 (260903) to the next GeoVision firmware release that addresses this issue; no fixed version is specified in the available data, so consult GeoVision's advisory for the patched build. Until patched, restrict the camera's VLSVR service to trusted management networks and avoid direct internet exposure, since the crash can be triggered remotely without authentication. If the VLSVR service has crashed, restarting the device restores service, but an attacker can re-trigger the crash until the firmware is updated.
| GeoVision GV-LPC2211 license plate recognition camera (VLSVR service) | V1.14 (260903) (named as affected; other version ranges not specified in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR service.
- Weakness
- CWE-121
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.