CVE-2026-88281: GeoVision Inc Gv-LPC2011/LPC2211
Medium severity, CVSS 4.9. EPSS: 0.4% chance of exploitation in the next 30 days.
GeoVision GV-LPC2211 V1.13 fails to limit repeated Username elements in ONVIF DeleteUsers requests, allowing an authenticated administrator to overflow a stack array and crash the ONVIF worker.
Affected products
- GeoVision Inc Gv-LPC2011/LPC2211: version 1.13 only
Published 2026-09-10. Last modified 2026-09-10.