GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR service.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.geovision.com.tw/cyber_security.php |
|
History
Thu, 10 Sep 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR service. | |
| Title | GV-LPC2011/LPC2211 - Multiple Pre-Authentication Stack Buffer Overflows in VLSVR Request Handlers | |
| First Time appeared |
Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211 |
|
| Weaknesses | CWE-121 | |
| CPEs | cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14_20260903:*:*:*:*:*:*:* cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14_20260909:*:*:*:*:*:*:* |
|
| Vendors & Products |
Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GV
Published:
Updated: 2026-09-10T08:25:41.380Z
Reserved: 2026-09-10T02:56:07.564Z
Link: CVE-2026-88289
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses