Session Cookie Vulnerability in GeoVision Web Interface
CVE-2026-42365

8.6HIGH

Key Information:

Vendor
CVE Published:
4 May 2026

What is CVE-2026-42365?

A vulnerability exists in the Web Interface of GeoVision LPC2011 and LPC2211, where a guessable session cookie can be exploited through a series of specifically crafted HTTP requests. This allows unauthorized users to potentially bypass authentication mechanisms, compromising the integrity of the affected systems. Attackers may execute brute force attacks on the session cookies, posing risks to sensitive data and overall security.

Affected Version(s)

GV-LPC2011/LPC2211 Linux 1.10

GV-LPC2011/LPC2211 Linux 1.12

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Philippe Laulheret of Cisco Talos.
Kelly Patterson of Cisco Talos.
Martin Zeiser of Cisco Talos.
.