CVE-2026-42367: GeoVision LPC2011/LPC2211 Web Interface / ssi.cgi privilege escalation vulnerability via leak of Administrator credentials
A privilege escalation vulnerability exists in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to credentials leak. An attacker can visit a webpage to trigger this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GeoVision GV-LPC2011/LPC2211to a version that resolves this vulnerability.Fixed in V1.12-260330
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42367?
CVE-2026-42367 is considered a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2026-42367?
To resolve CVE-2026-42367, update the GeoVision LPC2011 or LPC2211 to the latest version that addresses the vulnerability.
What systems are affected by CVE-2026-42367?
CVE-2026-42367 affects the GeoVision LPC2011 and LPC2211 models specifically running version 1.10.
What are the risks associated with CVE-2026-42367?
The main risk of CVE-2026-42367 is unauthorized access to administrative functionalities, potentially leading to further system compromises.
Is CVE-2026-42367 actively being exploited?
While it is not confirmed that CVE-2026-42367 is actively being exploited, the high severity indicates a significant risk if left unaddressed.