CVE-2026-88281: GeoVision Inc Gv-LPC2011/LPC2211

Medium severity, CVSS 4.9. EPSS: 0.4% chance of exploitation in the next 30 days.

GeoVision GV-LPC2211 V1.13 fails to limit repeated Username elements in ONVIF DeleteUsers requests, allowing an authenticated administrator to overflow a stack array and crash the ONVIF worker.

Affected products

Published 2026-09-10. Last modified 2026-09-10.