CVE-2026-88271: GV-LPC2011/LPC2211 - SSVR Guest Configuration Overwrite and Administrative Credential Takeover
Published Sep 10, 2026
·Updated
GeoVision GV-LPC2211 V1.13 allows a Guest user to overwrite device configuration and replace the administrator password through SSVR.
Affected Software
1 affected component
GeoVision GV-LPC2211=1.13
Event History
Sep 10, 2026
CVE Published
via MITRE·08:19 AM
Data Sourced
via MITRE·08:19 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attacker needs authenticated Guest-level access to the affected device. No user interaction is required, and the attack can be performed over the network.
2
What is the impact after successful exploitation?
A Guest user can overwrite device configuration through SSVR and replace the administrator password. This can lead to full compromise of confidentiality, integrity, and availability on the device.
3
Which version is identified as affected?
The affected version identified is GeoVision GV-LPC2211 V1.13.