Impact
GeoVision GV-LPC2211 firmware versions 1.13 and 1.14 contain a missing authorization flaw that allows a Guest user to request device configuration data via the SSVR service. The retrieved configuration includes plaintext administrative and user credentials, enabling an attacker to obtain privileged access to the device without proper authentication. This vulnerability is classified as CWE-862, which signifies the absence of required access controls.
Affected Systems
The affected products are GeoVision’s GV‑LPC2011 and GV‑LPC2211 devices running firmware versions 1.13 and 1.14. No other versions or product lines are listed as impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate to high severity, and the EPSS score is currently not available, so the systemic likelihood of exploitation is unknown. The vulnerability is not listed in CISA’s KEV catalog, implying no confirmed exploits are publicly known at this time. The likely attack vector is via the SSVR interface accessible to Guest users; since SSVR can be invoked over a network or local inter‑device channel, an attacker could exploit the flaw remotely if that interface is reachable. The primary consequence is unauthorized disclosure of credentials that could grant full administrative control of the device.
OpenCVE Enrichment