Impact
The vulnerability is an unauthenticated PTZ control service that returns camera movement data and accepts PTZ or raw serial commands. Absence of authentication allows any network client to query and manipulate the camera, which can lead to unauthorized surveillance control or manipulation of the device. The weakness is a CWE‑306 authentication failure, giving attackers full execution integrity of the PTZ service.
Affected Systems
GeoVision’s GV‑LPC2011/LPC2211 series, firmware 1.13 and 1.14, are affected. These on‑board components provide Pan‑Tilt‑Zoom functions in security cameras. No other versions or vendor references are listed.
Risk and Exploitability
The CVSS score of 9.4 signals a critical severity, and the EPSS score is not available, though the flaw is not yet included in CISA KEV. The likely attack vector is remote network connections to the PTZ port; an attacker only needs access to the device’s IP, no credentials, to issue commands. Exploitation would thereby grant an attacker control of camera positioning and potentially arbitrary serial commands, which could be used to tamper with or disrupt the device. The lack of authentication makes the vulnerability highly exploitable, especially on unsecured or publicly exposed cameras.
OpenCVE Enrichment