Geovision GV-LPC2211 V1.13 存在一个漏洞,允许经过身份验证的 ONVIF 用户通过 ConsumerReference.Address 字段注入 Shell 命令,从而以 root 权限执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GeoVision Inc. | GV-LPCLPC2011/2211 | 1.13 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88278 | 9.8 CRITICAL | GV-LPCLPC2011/2211 - ONVIF WS-Security PasswordDigest Replay |
| CVE-2026-88285 | 9.4 CRITICAL | GV-LPC2011/LPC2211 - Unauthenticated PTZ Control Service |
| CVE-2026-88271 | 8.8 HIGH | GV-LPC2011/LPC2211 - SSVR Guest Configuration Overwrite and Administrative Credential Take |
| CVE-2026-88290 | 7.5 HIGH | GV-LPC2011/LPC2211 - Unauthenticated VLSVR Slowloris and Memory Resource Exhaustion |
| CVE-2026-88289 | 7.5 HIGH | GV-LPC2011/LPC2211 - Multiple Pre-Authentication Stack Buffer Overflows in VLSVR Request H |
| CVE-2026-88287 | 7.5 HIGH | GV-LPC2011/LPC2211 -ONVIF Discovery Probe Scopes Stack-Frame Overflow Denial of Service |
| CVE-2026-88286 | 7.5 HIGH | GV-LPC2011/LPC2211 - PTZ Connection-State Accept-Loop Denial of Service |
| CVE-2026-88282 | 7.2 HIGH | GV-LPCLPC2011/2211 - Stored FTP-Username Command Injection |
| CVE-2026-88273 | 7.2 HIGH | GV-LPC2011/LPC2211 - PPPoE Username Shell-Configuration Command Injection |
| CVE-2026-88276 | 7.2 HIGH | GV-LPCLPC2011/2211 - Wireless WEP Key1-Key4 Command Injection |
| CVE-2026-88274 | 7.2 HIGH | GV-LPC2011/LPC2211 - Wireless SSID Command Injection |
| CVE-2026-88272 | 7.2 HIGH | GV-LPC2011/LPC2211 - Stored Administrator-Username Command Injection |
| CVE-2026-88275 | 7.2 HIGH | GV-LPC2011/LPC2211 - Wireless WPA-PSK Command Injection |
| CVE-2026-88269 | 6.5 MEDIUM | GV-LPC2011/LPC2211 - SSVR Guest Configuration and Credential Disclosure |
| CVE-2026-88270 | 6.5 MEDIUM | GV-LPC2011/LPC2211 - SSVR Guest Firmware-Mode Pre-Validation Service Teardown Denial of Se |
| CVE-2026-88268 | 6.5 MEDIUM | GV-LPC2011/LPC2211 - SSVR Fragment-Reassembly Stack Overflow Denial of Service |
| CVE-2026-88288 | 6.5 MEDIUM | GV-LPC2011/LPC2211 - Arbitrary File Read Through BKDownloadLink.cgi Symlink Creation |
| CVE-2026-88284 | 4.9 MEDIUM | GV-LPC2011/LPC2211 - ONVIF SetUser Repeated-Element Stack-Frame Overflow Denial of Service |
| CVE-2026-88281 | 4.9 MEDIUM | GV-LPC2011/LPC2211 - ONVIF DeleteUsers Repeated-Element Stack Overflow Denial of Service |
| CVE-2026-88279 | 4.9 MEDIUM | GV-LPC2011/LPC2211 - ONVIF CreateUsers Username/Password Stack-Frame Overflow Denial of Se |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet