CVE-2026-88284

Summary

GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF SetUser requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker.

Affected Software

VendorProductVersion RangeStatus
GeoVision Inc.GV-LPC2011/LPC2211 -1.13affected
GeoVision Inc.GV-LPC2011/LPC2211 -1.14unaffected

Weaknesses

  • CWE-121: CWE-121 Stack-based buffer overflow

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References