CVE-2026-88283
Deferred Deferred - Pending Action

Stack Overflow in GeoVision GV-LPC2211 ONVIF

Vulnerability report for CVE-2026-88283, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: GV

Description

GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF CreateUsers requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
geovision gv-lpc2211 1.13

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

GeoVision GV-LPC2211 V1.13 has a flaw where it does not restrict repeated User elements in ONVIF CreateUsers requests. An authenticated admin can exploit this to overwrite stack control data, causing the ONVIF worker process to crash.

Detection Guidance

This vulnerability involves repeated User elements in ONVIF CreateUsers requests causing stack corruption. Monitor ONVIF traffic for malformed CreateUsers requests with excessive User elements. Check system logs for crashes in the ONVIF worker process after authentication attempts.

Impact Analysis

This vulnerability could lead to denial-of-service conditions where the ONVIF service becomes unavailable. If the device relies on ONVIF for critical functions, it may disrupt surveillance or access control operations.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR, HIPAA, or similar standards as it involves a denial-of-service condition in a specific device (GeoVision GV-LPC2211) rather than data exposure or unauthorized access. However, if the device is part of a system handling regulated data, its instability could indirectly affect operational compliance by disrupting security controls or logging mechanisms.

Mitigation Strategies

Apply the latest firmware update from GeoVision if available. Restrict ONVIF access to trusted networks only. Disable ONVIF services if not required. Monitor for unusual authentication attempts or crashes in the ONVIF worker process.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88283. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart