ZeroHour

CVE-2026-88290

niche

Unauthenticated DoS via resource exhaustion in GeoVision GV-LPC2211 camera

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-88290 is an uncontrolled resource consumption flaw (CWE-400) in the GeoVision GV-LPC2211 license-plate-capture camera running firmware V1.14 (260903). An unauthenticated remote client can declare unbounded VLSVR frame lengths and then indefinitely stall blocking receive operations, causing the device to accumulate buffers, connections, and worker resources for each stalled client. By opening enough such connections, an attacker exhausts memory, connection slots, and workers, rendering the camera's service unavailable until resources are freed (e.g., by a restart); there is no confidentiality or confidentiality/integrity impact per the CVSS vector. Only deployments of this specific GeoVision camera model with the named firmware that expose the service to unauthenticated network clients are affected, which typically means parking, gate, and access-control installations. No public proof-of-concept exists, the issue is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported.

What to do: Check GeoVision's advisories for a firmware release newer than V1.14 (260903) and upgrade when a fix is published. Until then, restrict unauthenticated access to the camera's network services using firewall rules, ACLs, or VLAN segmentation so only trusted hosts (e.g., the LPR management server) can reach the device. If a camera becomes unresponsive, rebooting or restarting its service should clear the exhausted resources.

Affected
GeoVision GV-LPC2211 license plate capture IP cameraV1.14 (260903) firmware (the only version named in the advisory; affected range beyond this build not specified)
Estimated exposure
nichelikely on the order of thousands of units deployed worldwide, mostly on internal networks; internet-exposed count unknown — This is a single specialized license-plate-recognition camera model from one surveillance vendor, typically deployed at parking, gate, and access-control sites on controlled networks rather than in mass-market or broadly internet-facing…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker resources.

Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.