Description
GeoVision GV-LPC2211 V1.13 allows a Guest user to enter SSVR firmware-upgrade mode and disrupt live services before any firmware image is validated.
Published: 2026-09-10
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

GeoVision GV‑LPC2211 versions 1.13 and 1.14 expose a flaw that permits a Guest user to enter SSVR firmware‑upgrade mode without proper validation, causing live services to be torn down. The result is a disruption of availability, fitting the category of a Denial of Service vulnerability. The weakness is a missing access control (CWE‑862), which allows unauthenticated or low‑privileged users to trigger a service‑teardown sequence before the firmware image is verified.

Affected Systems

The affected devices are GEO Vision’s GV‑LPC2011/LPC2211 embedded controllers, specifically firmware releases 1.13 and 1.14 as listed by the vendor. These models run the SSVR firmware upgrade service and are deployed in security‑camera and surveillance hardware.

Risk and Exploitability

This vulnerability carries a CVSS score of 6.5, indicating moderate severity. No EPSS data is available, so current exploit likelihood is unknown, and the issue is not yet listed in the CISA KEV catalog. Based on the description, the likely attack vector is through device interfaces that allow a Guest user to submit upgrade commands, such as a web or local management console. The risk is that any attacker with access to a Guest account could disrupt device operation, impacting service availability.

Generated by OpenCVE AI on September 10, 2026 at 09:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the GV‑LPC2011/LPC2211 firmware to a version that eliminates the unchecked guest upgrade path (check GeoVision’s support portal for updates).
  • Disable or remove the Guest user’s ability to invoke the SSVR firmware‑upgrade function; reconfigure role‑based access controls to enforce the missing access control.
  • Network‑segregate or block external access to the device’s upgrade management interface so that only trusted administrators can perform firmware changes.

Generated by OpenCVE AI on September 10, 2026 at 09:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description GeoVision GV-LPC2211 V1.13 allows a Guest user to enter SSVR firmware-upgrade mode and disrupt live services before any firmware image is validated.
Title GV-LPC2011/LPC2211 - SSVR Guest Firmware-Mode Pre-Validation Service Teardown Denial of Service
First Time appeared Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211
Weaknesses CWE-862
CPEs cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*
Vendors & Products Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Geovision Inc. Gv-lpc2011 Lpc2211
cve-icon MITRE

Status: PUBLISHED

Assigner: GV

Published:

Updated: 2026-09-10T17:30:11.233Z

Reserved: 2026-09-10T02:56:02.025Z

Link: CVE-2026-88270

cve-icon Vulnrichment

Updated: 2026-09-10T17:30:03.768Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T09:17:03.883

Modified: 2026-09-10T18:18:15.007

Link: CVE-2026-88270

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T09:30:10Z

Weaknesses