CVE-2026-88269: GV-LPC2011/LPC2211 - SSVR Guest Configuration and Credential Disclosure
GeoVision GV-LPC2211 V1.13 allows a Guest user to retrieve persistent device configuration containing plaintext administrative and user credentials through SSVR.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GeoVision GV-LPC2011/LPC2211to a version that resolves this vulnerability.Fixed in V1.13 - Compensating control
Disable SSVR Guest access to prevent a Guest user from retrieving persistent device configuration (including plaintext administrative and user credentials).
Event History
Frequently Asked Questions
What level of access does an attacker need to retrieve the exposed configuration?
An attacker needs Guest-level access. No user interaction is required, and the issue is reachable over the network.
What information can be disclosed?
The Guest user can retrieve persistent device configuration through SSVR. That configuration contains plaintext administrative and user credentials.
What is the likely impact of the disclosed credentials?
Disclosure of plaintext administrative credentials could allow an attacker to authenticate with elevated device access. The reported impact is confidentiality loss; integrity and availability impacts are not indicated.