Impact
GeoVision GV‑LPC2211 firmware v1.14 allows an unauthenticated client to issue VLSVR commands with arbitrarily large frame lengths and to send fragments that delay blocking receives, causing the device to allocate excessive memory and spawn many worker threads until it runs out of resources. The vulnerability is a classic unbounded resource allocation flaw. Successful exploitation would result in degraded performance, dropped connections, and eventually a complete denial‑of‑service for legitimate users, without requiring any authentication or privileged access.
Affected Systems
The affected system is GeoVision’s GV‑LPC2011/LPC2211 product suite with firmware version 1.14 (revision 260903) as referenced by the CPE entries for 1.14_20260903 and 1.14_20260909. Only this vendor–product combination is reported to be impacted.
Risk and Exploitability
The CVSS score of 7.5 rates the vulnerability as a high‑severity issue. EPSS information is not available, and the vulnerability is not listed in CISA KEV, indicating no confirmed exploitation campaigns at the time of analysis. The attack can be launched from any network location that can reach the device and is unauthenticated, making it attractive for adversaries targeting accessible media servers or IoT gateways. The impact is system‑wide because resource exhaustion can affect all connections, and nobody can prevent the attack by simply relying on default authentications.
OpenCVE Enrichment