Impact
The vulnerability in GeoVision GV‑LPC2011/LPC2211 firmware allows a Guest user to overwrite device configuration via the SSVR interface and replace the administrator password. This missing authorization flaw (CWE‑862) gives the attacker full administrative control, enabling unilateral modification of system settings, persistence, and unauthorized data access.
Affected Systems
GeoVision Inc.’s GV‑LPC2011/LPC2211 devices running firmware version 1.13 are confirmed vulnerable. Firmware 1.14 is listed in the vulnerability scope but no evidence indicates it has been fixed, so it may remain affected.
Risk and Exploitability
The CVSS score of 8.8 signifies high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the SSVR service, which a Guest user can reach over the network to trigger the configuration overwrite and credential takeover. This inference is based on the description of the flaw allowing a Guest account to overwrite configuration.
OpenCVE Enrichment