Description
GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers username or password values into fixed stack fields, allowing an authenticated administrator to crash the ONVIF worker.
Published: 2026-09-10
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

GeoVision's GV‑LPC2011/LPC2211 firmware versions 1.13 and 1.14 are vulnerable to a stack‑frame overflow when an authenticated administrator submits an ONVIF CreateUsers request with an oversized username or password. The kernel copies the input string into a fixed size stack buffer, causing the ONVIF worker process to crash. The resulting denial of service can render the device unavailable until a reboot occurs. The flaw is a classic buffer overflow, classified as CWE‑121.

Affected Systems

The vulnerability affects GeoVision Inc. devices running GV‑LPC2011 or GV‑LPC2211 firmware version 1.13 and, as indicated by the CPE list, 1.14 as well. A successful exploit requires the attacker to have authenticated administrator privileges or to be able to send privileged ONVIF CreateUsers requests to the target device.

Risk and Exploitability

The CVSS base score of 4.9 indicates moderate severity. Exploit probability is unknown as the EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack requires valid administrator credentials or a channel to send ONVIF CreateUsers requests, implying that the attacker must have some level of remote or local access to the device.

Generated by OpenCVE AI on September 10, 2026 at 09:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a firmware update that removes the stack‑overflow bug.
  • If an update is unavailable, disable the ONVIF interface or restrict it to trusted local networks.
  • Enforce strict username and password length checks in the ONVIF service to prevent oversized values.

Generated by OpenCVE AI on September 10, 2026 at 09:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers username or password values into fixed stack fields, allowing an authenticated administrator to crash the ONVIF worker.
Title GV-LPC2011/LPC2211 - ONVIF CreateUsers Username/Password Stack-Frame Overflow Denial of Service
First Time appeared Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211
Weaknesses CWE-121
CPEs cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*
Vendors & Products Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Geovision Inc. Gv-lpc2011 Lpc2211
cve-icon MITRE

Status: PUBLISHED

Assigner: GV

Published:

Updated: 2026-09-10T15:25:30.611Z

Reserved: 2026-09-10T02:56:04.082Z

Link: CVE-2026-88279

cve-icon Vulnrichment

Updated: 2026-09-10T15:25:04.084Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T09:17:04.897

Modified: 2026-09-10T16:18:09.610

Link: CVE-2026-88279

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T09:30:10Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow