Description
GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker resources.
Published: 2026-09-10
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Resource Exhaustion (Denial of Service)
Action: Implement Limits
AI Analysis

Impact

GeoVision GV‑LPC2211 firmware v1.14 allows an unauthenticated client to issue VLSVR commands with arbitrarily large frame lengths and to send fragments that delay blocking receives, causing the device to allocate excessive memory and spawn many worker threads until it runs out of resources. The vulnerability is a classic unbounded resource allocation flaw. Successful exploitation would result in degraded performance, dropped connections, and eventually a complete denial‑of‑service for legitimate users, without requiring any authentication or privileged access.

Affected Systems

The affected system is GeoVision’s GV‑LPC2011/LPC2211 product suite with firmware version 1.14 (revision 260903) as referenced by the CPE entries for 1.14_20260903 and 1.14_20260909. Only this vendor–product combination is reported to be impacted.

Risk and Exploitability

The CVSS score of 7.5 rates the vulnerability as a high‑severity issue. EPSS information is not available, and the vulnerability is not listed in CISA KEV, indicating no confirmed exploitation campaigns at the time of analysis. The attack can be launched from any network location that can reach the device and is unauthenticated, making it attractive for adversaries targeting accessible media servers or IoT gateways. The impact is system‑wide because resource exhaustion can affect all connections, and nobody can prevent the attack by simply relying on default authentications.

Generated by OpenCVE AI on September 10, 2026 at 09:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply limits on VLSVR frame size and fragment timing to avoid unbounded allocation.
  • Use firewall or network segmentation to block unauthenticated traffic to the GV‑LPC2211 device.
  • Continuously monitor memory usage, connection counts, and worker thread activity, and reset or reboot the device when thresholds are exceeded.

Generated by OpenCVE AI on September 10, 2026 at 09:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker resources.
Title GV-LPC2011/LPC2211 - Unauthenticated VLSVR Slowloris and Memory Resource Exhaustion
First Time appeared Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211
Weaknesses CWE-400
CPEs cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14_20260903:*:*:*:*:*:*:*
cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14_20260909:*:*:*:*:*:*:*
Vendors & Products Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Geovision Inc. Gv-lpc2011 Lpc2211
cve-icon MITRE

Status: PUBLISHED

Assigner: GV

Published:

Updated: 2026-09-10T15:04:23.966Z

Reserved: 2026-09-10T02:56:08.894Z

Link: CVE-2026-88290

cve-icon Vulnrichment

Updated: 2026-09-10T15:04:13.835Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T09:17:06.133

Modified: 2026-09-10T16:18:10.767

Link: CVE-2026-88290

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:45:17Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption