Privilege Escalation in Web Interface of GeoVision LPC2011/LPC2211
CVE-2026-42368

9.9CRITICAL

Key Information:

Vendor
CVE Published:
4 May 2026

What is CVE-2026-42368?

A privilege escalation vulnerability has been identified within the Web Interface of the GeoVision LPC2011 and LPC2211 models, version 1.10. An attacker could exploit this vulnerability by crafting a specific HTTP request, allowing unauthorized execution of privileged operations on the system. By visiting a compromised webpage, an attacker can trigger this vulnerability, potentially leading to unauthorized access and control over the affected devices. Users of GeoVision LPC2011 and LPC2211 should take immediate action to secure their systems against this threat.

Affected Version(s)

GV-LPC2011/LPC2211 Linux 1.10

GV-LPC2011/LPC2211 Linux 1.2

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Philippe Laulheret of Cisco Talos.
Kelly Patterson of Cisco Talos.
Martin Zeiser of Cisco Talos.
.