Description
GeoVision GV-LPC2211 V1.13 allows a Guest user to retrieve persistent device configuration containing plaintext administrative and user credentials through SSVR.
Published: 2026-09-10
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Credential Disclosure
Action: Assess Impact
AI Analysis

Impact

GeoVision GV-LPC2211 firmware versions 1.13 and 1.14 contain a missing authorization flaw that allows a Guest user to request device configuration data via the SSVR service. The retrieved configuration includes plaintext administrative and user credentials, enabling an attacker to obtain privileged access to the device without proper authentication. This vulnerability is classified as CWE-862, which signifies the absence of required access controls.

Affected Systems

The affected products are GeoVision’s GV‑LPC2011 and GV‑LPC2211 devices running firmware versions 1.13 and 1.14. No other versions or product lines are listed as impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate to high severity, and the EPSS score is currently not available, so the systemic likelihood of exploitation is unknown. The vulnerability is not listed in CISA’s KEV catalog, implying no confirmed exploits are publicly known at this time. The likely attack vector is via the SSVR interface accessible to Guest users; since SSVR can be invoked over a network or local inter‑device channel, an attacker could exploit the flaw remotely if that interface is reachable. The primary consequence is unauthorized disclosure of credentials that could grant full administrative control of the device.

Generated by OpenCVE AI on September 10, 2026 at 09:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify the firmware version on each GV‑LPC2011/LPC2211 device and upgrade to the latest patched release if one is available.
  • Restrict or disable the SSVR service for Guest accounts to eliminate the privilege gap causing the disclosure.
  • Change all default or stored credentials on the device and enable strong authentication policies to mitigate the impact of any remaining exposure.
  • Implement routine monitoring of configuration access logs to detect anomalous activity that could indicate exploitation of this flaw.

Generated by OpenCVE AI on September 10, 2026 at 09:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description GeoVision GV-LPC2211 V1.13 allows a Guest user to retrieve persistent device configuration containing plaintext administrative and user credentials through SSVR.
Title GV-LPC2011/LPC2211 - SSVR Guest Configuration and Credential Disclosure
First Time appeared Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211
Weaknesses CWE-862
CPEs cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*
Vendors & Products Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Geovision Inc. Gv-lpc2011 Lpc2211
cve-icon MITRE

Status: PUBLISHED

Assigner: GV

Published:

Updated: 2026-09-10T12:50:08.057Z

Reserved: 2026-09-10T02:56:02.025Z

Link: CVE-2026-88269

cve-icon Vulnrichment

Updated: 2026-09-10T12:49:57.993Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T09:17:03.770

Modified: 2026-09-10T15:13:07.090

Link: CVE-2026-88269

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T09:30:10Z

Weaknesses