CVE-2026-88287: GV-LPC2011/LPC2211 -ONVIF Discovery Probe Scopes Stack-Frame Overflow Denial of Service
Published Sep 10, 2026
·Updated
GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens in unauthenticated ONVIF WS-Discovery Probe requests, allowing a remote attacker to corrupt stack control state and crash the discovery process.
Affected Software
1 affected component
GeoVision GV-LPC2211=V1.13
Event History
Sep 10, 2026
CVE Published
via MITRE·08:24 AM
Data Sourced
via MITRE·08:24 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A remote, unauthenticated attacker can exploit it by sending ONVIF WS-Discovery Probe requests containing an excessive number of Scopes tokens. No user interaction or prior privileges are required.
2
What is the expected impact of successful exploitation?
Successful exploitation can corrupt stack control state and crash the device's discovery process, resulting in a denial of service. The provided severity vector indicates no confidentiality or integrity impact.
3
Which version is identified as affected?
The affected version identified in the available data is GeoVision GV-LPC2211 V1.13.