Impact
A privilege escalation vulnerability exists in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request triggers a leakage of Administrator credentials, allowing an attacker to acquire elevated privileges. This flaw is classified as CWE‑522, which denotes insecure storage of credentials. The vulnerability can compromise confidentiality and control over the device if exploited, but it does not necessarily grant immediate remote code execution.
Affected Systems
The affected vendors and products are GeoVision Inc. – GV‑LPC2011/LPC2211. The specific firmware version known to be vulnerable is v1.10; the newer v1.20 firmware is not listed as affected in the description. Users running firmware 1.10 or earlier on the GV‑LPC2011/LPC2211 models should review their software version.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate to high risk. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, but the attack can be performed remotely by issuing an HTTP request to the ssi.cgi endpoint. An attacker with network access to the web interface can exploit the flaw without specialized authentication, potentially obtaining administrator credentials and escalating privileges within the device.
OpenCVE Enrichment