GeoVision LPC2011和GeoVision LPC2211都是中国GeoVision公司的一款网络监控控制设备。 GeoVision LPC2011和GeoVision LPC2211 1.10版本存在跨站脚本漏洞,该漏洞源于Web Interface的ssi.cgi功能存在反射型跨站脚本,特制恶意URL可能导致任意JavaScript代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GeoVision Inc. | GV-LPC2011/LPC2211 | V1.10 |
affected |
V1.20 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GeoVision Inc. | GV-LPC2011/LPC2211 | V1.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42369 | 10.0 CRITICAL | GeoVision GV-VMS V20 WebCam Server stack overflow vulnerability |
| CVE-2026-42368 | 9.9 CRITICAL | GeoVision LPC2011/LPC2211 Web Interface privilege escalation vulnerability |
| CVE-2026-42364 | 9.9 CRITICAL | GeoVision LPC2011/LPC2211 Web Interface / DdnsSetting.cgi OS command injection vulnerabili |
| CVE-2026-7161 | 9.3 CRITICAL | GeoVision GV-IP Device Utility Device Authentication insufficient encryption vulnerability |
| CVE-2026-42370 | 9.0 CRITICAL | GeoVision GV-VMS V20 WebCam Server Login stack overflow vulnerability |
| CVE-2026-7372 | 9.0 CRITICAL | GeoVision GV-VMS V20 WebCam Server Login stack overflow vulnerability |
| CVE-2026-42365 | 8.6 HIGH | GeoVision LPC2011/LPC2211 Web Interface guessable session cookie vulnerability |
| CVE-2026-42366 | 7.4 HIGH | GeoVision LPC2011/LPC2211 Web Interface / ssi.cgi reflected cross-site scripting (XSS) vul |
| CVE-2026-42367 | 6.5 MEDIUM | GeoVision LPC2011/LPC2211 Web Interface / ssi.cgi privilege escalation vulnerability via l |
No comments yet