CVE-2026-88289: GeoVision Inc Gv-LPC2011/LPC2211

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR service.

Affected products

Published 2026-09-10. Last modified 2026-09-10.