CVE-2026-7371: GeoVision LPC2011/LPC2211 Web Interface / ssi.cgi reflected cross-site scripting (XSS) vulnerabilities
Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. Reflected XXS via the error message for requesting non-existing page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GeoVision GV-LPC2011/LPC2211to a version that resolves this vulnerability.Fixed in V1.12-260330 - Upgrade
Upgrade
GeoVision LPC2011/LPC2211to a version that resolves this vulnerability.Fixed in 1.10 - Compensating control
Until the device is updated, restrict access to the GeoVision web interface (Web Interface / ssi.cgi) so attackers cannot trigger the crafted URL XSS/reflected XSS payloads.
Event History
Frequently Asked Questions
What are the potential impacts of CVE-2026-7371?
CVE-2026-7371 can lead to unauthorized execution of scripts in the user's browser, enabling attackers to steal session cookies or perform actions on behalf of the user.
How can I determine if my system is affected by CVE-2026-7371?
If you are using GeoVision LPC2011 or LPC2211 with version 1.10, your system is likely affected by CVE-2026-7371.
How do I fix CVE-2026-7371?
To mitigate CVE-2026-7371, you should update to the latest firmware version provided by GeoVision that addresses these reflective XSS vulnerabilities.
What kind of attack vectors does CVE-2026-7371 expose?
CVE-2026-7371 exposes attack vectors that allow attackers to craft malicious URLs triggering XSS attacks through the Web Interface.
Is CVE-2026-7371 a critical vulnerability?
CVE-2026-7371 is considered a significant security concern due to its potential for exploitation via reflected XSS, which could compromise user data.