8.6

CVE-2026-42365

GeoVision LPC2011/LPC2211 Web Interface guessable session cookie vulnerability

A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. An attacker can bruteforce session cookies to trigger this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GeovisionGv-lpc2011 Firmware Version1.10
   GeovisionGv-lpc2011 Version-
GeovisionGv-lpc2211 Firmware Version1.10
   GeovisionGv-lpc2211 Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.33% 0.244
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
0df08a0e-a200-4957-9bb0-084f562506f9 8.6 3.9 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CWE-341 Predictable from Observable State

A number or object is predictable based on observations that the attacker can make about the state of the system or network, such as time, process ID, etc.

https://www.geovision.com.tw/cyber_security.php
Vendor Advisory
https://talosintelligence.com/vulnerability_reports/
Third Party Advisory
https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2332