Description
GeoVision GV-LPC2211 V1.13 allows a Guest user to overwrite device configuration and replace the administrator password through SSVR.
Published: 2026-09-10
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Administrative Credential Takeover
Action: Patch
AI Analysis

Impact

The vulnerability in GeoVision GV‑LPC2011/LPC2211 firmware allows a Guest user to overwrite device configuration via the SSVR interface and replace the administrator password. This missing authorization flaw (CWE‑862) gives the attacker full administrative control, enabling unilateral modification of system settings, persistence, and unauthorized data access.

Affected Systems

GeoVision Inc.’s GV‑LPC2011/LPC2211 devices running firmware version 1.13 are confirmed vulnerable. Firmware 1.14 is listed in the vulnerability scope but no evidence indicates it has been fixed, so it may remain affected.

Risk and Exploitability

The CVSS score of 8.8 signifies high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the SSVR service, which a Guest user can reach over the network to trigger the configuration overwrite and credential takeover. This inference is based on the description of the flaw allowing a Guest account to overwrite configuration.

Generated by OpenCVE AI on September 10, 2026 at 10:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy firmware updates that address the SSVR guest overwrite flaw (if an official fix is released).
  • Restrict network access to the SSVR interface by configuring firewalls or segmentation to limit Guest user traffic.
  • Disable or delete the Guest user account when it is not required, and enforce stricter authentication for configuration changes.

Generated by OpenCVE AI on September 10, 2026 at 10:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description GeoVision GV-LPC2211 V1.13 allows a Guest user to overwrite device configuration and replace the administrator password through SSVR.
Title GV-LPC2011/LPC2211 - SSVR Guest Configuration Overwrite and Administrative Credential Takeover
First Time appeared Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211
Weaknesses CWE-862
CPEs cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*
Vendors & Products Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Geovision Inc. Gv-lpc2011 Lpc2211
cve-icon MITRE

Status: PUBLISHED

Assigner: GV

Published:

Updated: 2026-09-10T17:29:05.605Z

Reserved: 2026-09-10T02:56:02.025Z

Link: CVE-2026-88271

cve-icon Vulnrichment

Updated: 2026-09-10T17:28:15.661Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T09:17:04.003

Modified: 2026-09-10T18:18:15.167

Link: CVE-2026-88271

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T10:30:04Z

Weaknesses