CVE-2026-88290
nicheUnauthenticated DoS via resource exhaustion in GeoVision GV-LPC2211 camera
CVE-2026-88290 is an uncontrolled resource consumption flaw (CWE-400) in the GeoVision GV-LPC2211 license-plate-capture camera running firmware V1.14 (260903). An unauthenticated remote client can declare unbounded VLSVR frame lengths and then indefinitely stall blocking receive operations, causing the device to accumulate buffers, connections, and worker resources for each stalled client. By opening enough such connections, an attacker exhausts memory, connection slots, and workers, rendering the camera's service unavailable until resources are freed (e.g., by a restart); there is no confidentiality or confidentiality/integrity impact per the CVSS vector. Only deployments of this specific GeoVision camera model with the named firmware that expose the service to unauthenticated network clients are affected, which typically means parking, gate, and access-control installations. No public proof-of-concept exists, the issue is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported.
What to do: Check GeoVision's advisories for a firmware release newer than V1.14 (260903) and upgrade when a fix is published. Until then, restrict unauthenticated access to the camera's network services using firewall rules, ACLs, or VLAN segmentation so only trusted hosts (e.g., the LPR management server) can reach the device. If a camera becomes unresponsive, rebooting or restarting its service should clear the exhausted resources.
| GeoVision GV-LPC2211 license plate capture IP camera | V1.14 (260903) firmware (the only version named in the advisory; affected range beyond this build not specified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker resources.
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.