CVE-2026-88285: GV-LPC2011/LPC2211 - Unauthenticated PTZ Control Service
Published Sep 10, 2026
·Updated
GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve PTZ information and issue PTZ or raw serial commands.
Affected Software
1 affected component
GeoVision GV-LPC2211=V1.13
Event History
Sep 10, 2026
CVE Published
via MITRE·08:24 AM
Data Sourced
via MITRE·08:24 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any remote client that can reach the device's network-accessible PTZ control service can retrieve PTZ information and issue PTZ or raw serial commands. No authentication or user interaction is required.
2
What functions can an attacker control?
An attacker can obtain PTZ information, send PTZ commands, and issue raw serial commands through the exposed service.
3
Which product version is identified as affected?
The reported affected version is GeoVision GV-LPC2211 V1.13.