CVE-2026-88288: GV-LPC2011/LPC2211 - Arbitrary File Read Through BKDownloadLink.cgi Symlink Creation
Published Sep 10, 2026
·Updated
GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a remote user with valid web credentials to read arbitrary files accessible to the root-run web service.
Affected Software
1 affected component
GeoVision GV-LPC2211=V1.13
Event History
Sep 10, 2026
CVE Published
via MITRE·08:25 AM
Data Sourced
via MITRE·08:25 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A remote attacker needs valid web credentials. The affected component runs as root, so files readable by the root-run web service may be exposed.
2
What access does an attacker need to obtain sensitive files?
The attacker must be able to authenticate to the device's web interface and supply a crafted filename to BKDownloadLink.cgi. No user interaction is required.
3
How can I determine whether a device is affected?
The reported affected product and version are GeoVision GV-LPC2211 V1.13. Review whether authenticated users can access BKDownloadLink.cgi and monitor for unexpected filename requests or symlink creation associated with that endpoint.