CVE-2026-88286: GV-LPC2011/LPC2211 - PTZ Connection-State Accept-Loop Denial of Service
GeoVision GV-LPC2211 V1.13 improperly manages PTZ connection state, allowing an unauthenticated remote client to block the accept loop and prevent new PTZ connections.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated remote client that can reach the PTZ service on an affected GeoVision GV-LPC2211 V1.13 device can exploit it. No user interaction or existing account is required.
What is the operational impact?
An attacker can block the PTZ connection accept loop, preventing new PTZ connections from being established. The stated impact is denial of service; no confidentiality or integrity impact is indicated.
How can I determine whether a device is affected?
The affected product and version identified are GeoVision GV-LPC2211 V1.13. Devices running that version should be treated as potentially vulnerable if their PTZ service is reachable by remote clients.