CVE-2026-42365: GeoVision LPC2011/LPC2211 Web Interface guessable session cookie vulnerability
A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. An attacker can bruteforce session cookies to trigger this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GeoVision LPC2011/LPC2211 Web Interfaceto a version that resolves this vulnerability.Fixed in V1.12-260330 - Compensating control
Limit exposure of the Web Interface (e.g., restrict access via firewall/ACL) to reduce the ability to bruteforce session cookies and attempt authentication bypass until the firmware is updated to V1.12-260330.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42365?
CVE-2026-42365 is classified as a high severity vulnerability due to its potential for allowing unauthorized access.
How do I fix CVE-2026-42365?
To fix CVE-2026-42365, update the GeoVision LPC2011 or LPC2211 Web Interface software to a version that addresses the session cookie vulnerability.
What type of vulnerability is CVE-2026-42365?
CVE-2026-42365 is a guessable session cookie vulnerability that can lead to authentication bypass.
Who is affected by CVE-2026-42365?
CVE-2026-42365 affects users of the GeoVision LPC2011 and LPC2211 Web Interfaces running version 1.10.
What can an attacker do with CVE-2026-42365?
An attacker exploiting CVE-2026-42365 can perform brute-force attacks to gain unauthorized access to the Web Interface.