CVE-2026-88280: GV-LPC2011/LPC2211 - ONVIF SetUser Stack-Frame Overflow Denial of Service
GeoVision GV-LPC2211 V1.13 copies an oversized ONVIF SetUser password into a fixed stack field, allowing an authenticated administrator to crash the ONVIF worker.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GeoVision GV-LPC2011/LPC2211 ONVIFto a version that resolves this vulnerability.Fixed in V1.13 - Compensating control
Use compensating controls to limit exposure of the ONVIF service to trusted networks/clients until the device is updated.
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs network access to the device's ONVIF service and authenticated administrator privileges. The available information does not indicate that lower-privileged or unauthenticated users can trigger it.
What is the operational impact of successful exploitation?
A successful oversized ONVIF SetUser password request crashes the ONVIF worker, causing a denial of service for that component. The provided information does not describe confidentiality impact, integrity impact, code execution, or persistence.
How can administrators reduce exposure if they cannot patch immediately?
Restrict network access to the ONVIF service to trusted administrative systems and limit administrator credentials to only necessary personnel. Because exploitation requires an authenticated administrator, protecting and reviewing administrative account access is especially important.
How can I determine whether a device may be affected?
The reported affected product and version is GeoVision GV-LPC2211 V1.13. Devices matching that model and version should be treated as potentially affected, particularly if ONVIF is reachable by administrator accounts.