Description
GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve PTZ information and issue PTZ or raw serial commands.
Published: 2026-09-10
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an unauthenticated PTZ control service that returns camera movement data and accepts PTZ or raw serial commands. Absence of authentication allows any network client to query and manipulate the camera, which can lead to unauthorized surveillance control or manipulation of the device. The weakness is a CWE‑306 authentication failure, giving attackers full execution integrity of the PTZ service.

Affected Systems

GeoVision’s GV‑LPC2011/LPC2211 series, firmware 1.13 and 1.14, are affected. These on‑board components provide Pan‑Tilt‑Zoom functions in security cameras. No other versions or vendor references are listed.

Risk and Exploitability

The CVSS score of 9.4 signals a critical severity, and the EPSS score is not available, though the flaw is not yet included in CISA KEV. The likely attack vector is remote network connections to the PTZ port; an attacker only needs access to the device’s IP, no credentials, to issue commands. Exploitation would thereby grant an attacker control of camera positioning and potentially arbitrary serial commands, which could be used to tamper with or disrupt the device. The lack of authentication makes the vulnerability highly exploitable, especially on unsecured or publicly exposed cameras.

Generated by OpenCVE AI on September 10, 2026 at 09:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest GeoVision firmware that fixes the unauthenticated PTZ control issue (if available).
  • Restrict network access to the device by configuring firewall rules or placing cameras behind a DMZ, limiting the PTZ port to trusted IP ranges only.
  • If it is not necessary for remote PTZ control, disable the PTZ service or lock the camera to prevent external commands.

Generated by OpenCVE AI on September 10, 2026 at 09:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve PTZ information and issue PTZ or raw serial commands.
Title GV-LPC2011/LPC2211 - Unauthenticated PTZ Control Service
First Time appeared Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211
Weaknesses CWE-306
CPEs cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*
Vendors & Products Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H'}


Subscriptions

Geovision Inc. Gv-lpc2011 Lpc2211
cve-icon MITRE

Status: PUBLISHED

Assigner: GV

Published:

Updated: 2026-09-10T15:08:11.408Z

Reserved: 2026-09-10T02:56:04.083Z

Link: CVE-2026-88285

cve-icon Vulnrichment

Updated: 2026-09-10T15:08:06.087Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T09:17:05.563

Modified: 2026-09-10T16:18:10.260

Link: CVE-2026-88285

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:45:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function