CVE-2026-42368: GeoVision LPC2011/LPC2211 Web Interface privilege escalation vulnerability
A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to execute priviledged operation. An attacker can visit a webpage to trigger this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GeoVision GV-LPC2011/LPC2211to a version that resolves this vulnerability.Fixed in V1.12-260330
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42368?
The severity of CVE-2026-42368 is classified as critical due to its potential for privilege escalation allowing unauthorized access to privileged operations.
How do I fix CVE-2026-42368?
To fix CVE-2026-42368, update the affected GeoVision LPC2011 or LPC2211 Web Interface to the latest version that addresses this vulnerability.
What systems are impacted by CVE-2026-42368?
CVE-2026-42368 affects GeoVision LPC2011 and LPC2211 models specifically running version 1.10.
What type of attack is associated with CVE-2026-42368?
CVE-2026-42368 is associated with a privilege escalation attack that can be executed through crafted HTTP requests.
Is there a workaround for CVE-2026-42368 while waiting for a patch?
Currently, there are no known workarounds for CVE-2026-42368, and users are advised to apply the available patch as soon as possible.