CVE-2026-88289: GeoVision Inc Gv-LPC2011/LPC2211
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR service.
Affected products
- GeoVision Inc Gv-LPC2011/LPC2211: version 1.14 20260903 only
Published 2026-09-10. Last modified 2026-09-10.