CVE-2026-88279
- EPSS 0.25%
- Veröffentlicht 10.09.2026 08:22:12
- Zuletzt bearbeitet 10.09.2026 16:18:09
GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers username or password values into fixed stack fields, allowing an authenticated administrator to crash the ONVIF worker.
CVE-2026-88278
- EPSS 0.27%
- Veröffentlicht 10.09.2026 08:21:58
- Zuletzt bearbeitet 10.09.2026 16:18:09
GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations.
CVE-2026-88277
- EPSS 0.34%
- Veröffentlicht 10.09.2026 08:21:43
- Zuletzt bearbeitet 10.09.2026 18:18:15
GeoVision GV-LPC2211 V1.13 allows an authenticated ONVIF user to inject shell commands through ConsumerReference.Address and execute arbitrary commands as root.
CVE-2026-88276
- EPSS 0.37%
- Veröffentlicht 10.09.2026 08:21:28
- Zuletzt bearbeitet 10.09.2026 16:18:09
GeoVision GV-LPC2211 V1.13 allows administrator-controlled WEP key values containing shell syntax to execute arbitrary commands as root.
CVE-2026-88275
- EPSS 0.37%
- Veröffentlicht 10.09.2026 08:20:58
- Zuletzt bearbeitet 10.09.2026 16:18:09
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to execute arbitrary commands as root when wireless configuration is applied.
CVE-2026-88274
- EPSS 0.37%
- Veröffentlicht 10.09.2026 08:20:27
- Zuletzt bearbeitet 10.09.2026 16:18:09
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless SSID containing shell syntax to execute arbitrary commands as root.
CVE-2026-88273
- EPSS 0.37%
- Veröffentlicht 10.09.2026 08:20:07
- Zuletzt bearbeitet 10.09.2026 16:18:09
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a sourced shell configuration assignment and execute arbitrary commands as root.
CVE-2026-88272
- EPSS 0.3%
- Veröffentlicht 10.09.2026 08:19:47
- Zuletzt bearbeitet 10.09.2026 18:18:15
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled username containing shell metacharacters to be executed as arbitrary root commands when the stored username is later deleted.
CVE-2026-88271
- EPSS 0.23%
- Veröffentlicht 10.09.2026 08:19:30
- Zuletzt bearbeitet 10.09.2026 18:18:15
GeoVision GV-LPC2211 V1.13 allows a Guest user to overwrite device configuration and replace the administrator password through SSVR.
CVE-2026-88270
- EPSS 0.21%
- Veröffentlicht 10.09.2026 08:19:10
- Zuletzt bearbeitet 10.09.2026 18:18:15
GeoVision GV-LPC2211 V1.13 allows a Guest user to enter SSVR firmware-upgrade mode and disrupt live services before any firmware image is validated.