Impact
GeoVision’ GV‑LPC2211 firmware versions 1.13 and 1.14 allow a web user who possesses valid credentials to download any file the web service can read by manipulating the filename supplied to BKDownloadLink.cgi. The CGI component fails to validate the path, enabling the creation of a symlink that resolves to an arbitrary target file. This flaw provides an attacker with the confidential information or configuration data stored on the device, without requiring privilege escalation beyond the authenticated web session. The weakness is a classic absolute path traversal as identified by CWE‑36.
Affected Systems
The vulnerability affects GeoVision Inc.’s GV‑LPC2011 and GV‑LPC2211 devices running firmware 1.13 or 1.14. No other versions are noted as impacted.
Risk and Exploitability
The CVSS base score is 6.5, indicating a moderate severity. No EPSS score is available, so the exploitation probability is unknown, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote HTTP request to BKDownloadLink.cgi with valid authentication, which an attacker could use to read sensitive files as long as the device permits the web service to access them.
OpenCVE Enrichment