CVE-2026-88290: GV-LPC2011/LPC2211 - Unauthenticated VLSVR Slowloris and Memory Resource Exhaustion
Published Sep 10, 2026
·Updated
GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker resources.
Affected Software
1 affected component
GeoVision GV-LPC2011/LPC2211=V1.14 (260903)
Event History
Sep 10, 2026
CVE Published
via MITRE·08:26 AM
Data Sourced
via MITRE·08:26 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any unauthenticated remote client that can reach the affected device's VLSVR service can exploit it. No credentials or user interaction are required.
2
What is the likely impact of exploitation?
An attacker can declare unbounded VLSVR frame lengths and delay blocking receives, consuming memory, connections, and worker resources. This can cause a denial of service.
3
Which versions are identified as affected?
The reported affected version is GeoVision GV-LPC2211 V1.14 (260903). The provided information does not identify other affected or fixed versions.