CVE-2026-42366: GeoVision LPC2011/LPC2211 Web Interface / ssi.cgi reflected cross-site scripting (XSS) vulnerabilities
Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GeoVision GV-LPC2011/LPC2211to a version that resolves this vulnerability.Fixed in V1.12-260330 - Upgrade
Upgrade
GeoVision LPC2011/LPC2211to a version that resolves this vulnerability.Fixed in 1.10 - Compensating control
Use GeoVision GV-LPC2011/LPC2211 Web Interface access controls (e.g., block or restrict access to the affected ssi.cgi endpoint) until the device firmware is updated to V1.12-260330.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42366?
CVE-2026-42366 has been classified as a medium-severity vulnerability due to its potential for reflected cross-site scripting attacks.
How do I fix CVE-2026-42366?
To mitigate CVE-2026-42366, it is recommended to apply any available security patches from GeoVision for the LPC2011 and LPC2211 models.
What are the symptoms of CVE-2026-42366 exploitation?
Exploitation of CVE-2026-42366 may result in unauthorized script execution in the user’s web browser when they access a malicious URL.
Which products are affected by CVE-2026-42366?
CVE-2026-42366 affects the GeoVision LPC2011 and LPC2211 web interface versions 1.10.
Is CVE-2026-42366 a common vulnerability?
CVE-2026-42366 can be considered common due to the nature of reflected cross-site scripting vulnerabilities being prevalent in web applications.