Description
GeoVision GV-LPC2211 V1.13 fails to limit repeated Username elements in ONVIF DeleteUsers requests, allowing an authenticated administrator to overflow a stack array and crash the ONVIF worker.
Published: 2026-09-10
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Assess Impact
AI Analysis

Impact

The vulnerability is a stack buffer overflow caused by the ONVIF DeleteUsers operation failing to limit repeated Username elements. When an authenticated administrator submits a request with many Username entries, the service overflows an array and crashes. This results in a denial‑of‑service for the ONVIF interface, potentially blocking camera control or monitoring. The weakness follows CWE‑121, a stack‑based buffer overflow.

Affected Systems

The flaw has been identified in GeoVision Inc.'s GV‑LPC2011/LPC2211 firmware version 1.13. The CPE data includes firmware 1.14 as well, but the advisory does not confirm whether 1.14 contains the fix or remains vulnerable. Therefore, devices running 1.13, and by default 1.14 unless otherwise noted, should be considered potentially affected.

Risk and Exploitability

The CVSS score of 4.9 points to moderate severity. Exploitation requires authenticated administrative access, indicating an internally‑derived attacker or compromised admin credentials. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported. Nevertheless, any administrator who can issue privileged DeleteUsers requests could repeatedly crash the service, disrupting camera availability.

Generated by OpenCVE AI on September 10, 2026 at 10:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify the device firmware version; if it is 1.13 or another unpatched release, apply the vendor‑supplied firmware update that fixes the stack overflow, if such an update is available.
  • If firmware cannot be updated immediately, restrict ONVIF DeleteUsers access so that only trusted local administrators can issue requests, limiting the attack surface.
  • Monitor system logs for worker restarts or stack‑overflow errors, and investigate any unexpected crashes as potential exploitation attempts.

Generated by OpenCVE AI on September 10, 2026 at 10:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description GeoVision GV-LPC2211 V1.13 fails to limit repeated Username elements in ONVIF DeleteUsers requests, allowing an authenticated administrator to overflow a stack array and crash the ONVIF worker.
Title GV-LPC2011/LPC2211 - ONVIF DeleteUsers Repeated-Element Stack Overflow Denial of Service
First Time appeared Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211
Weaknesses CWE-121
CPEs cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*
Vendors & Products Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Geovision Inc. Gv-lpc2011 Lpc2211
cve-icon MITRE

Status: PUBLISHED

Assigner: GV

Published:

Updated: 2026-09-10T15:15:14.057Z

Reserved: 2026-09-10T02:56:04.082Z

Link: CVE-2026-88281

cve-icon Vulnrichment

Updated: 2026-09-10T15:14:12.772Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T09:17:05.117

Modified: 2026-09-10T16:18:09.867

Link: CVE-2026-88281

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:45:17Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow