Stack Overflow Vulnerability in GeoVision ONVIF System
CVE-2026-88284
4.9MEDIUM
What is CVE-2026-88284?
GeoVision GV-LPC2211 V1.13 contains a stack overflow vulnerability in its ONVIF SetUser request handling. This flaw allows an authenticated administrator to manipulate user elements excessively, leading to potential overwriting of the stack control state. As a result, this manipulation can cause the ONVIF worker to crash, which may disrupt system functionality and availability. Organizations using this product should review their configurations and apply necessary security measures to mitigate this risk.
Affected Version(s)
GV-LPC2011/LPC2211 - 1.13
GV-LPC2011/LPC2211 - 1.14
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University
