CVE-2026-88278: GV-LPCLPC2011/2211 - ONVIF WS-Security PasswordDigest Replay
Published Sep 10, 2026
·Updated
GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations.
Affected Software
1 affected component
GeoVision GV-LPC2211=V1.13
Event History
Sep 10, 2026
CVE Published
via MITRE·08:21 AM
Data Sourced
via MITRE·08:21 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The attacker needs to capture a valid WS-Security UsernameToken PasswordDigest token. That captured token can then be replayed to perform subsequent ONVIF operations.
2
Is authentication required for exploitation?
No separate attacker authentication is required according to the provided vector. However, exploitation depends on obtaining a previously valid PasswordDigest token to replay.
3
How can I determine whether the device is affected?
The affected product identified is GeoVision GV-LPC2211 running V1.13. Systems using that model and version should be treated as affected unless vendor guidance indicates otherwise.