Network-Accessible PTZ Control Vulnerability in GeoVision Products
CVE-2026-88285
9.4CRITICAL
What is CVE-2026-88285?
The GeoVision GV-LPC2211 V1.13 has a serious flaw that exposes its PTZ (pan-tilt-zoom) control service over the network without proper authentication mechanisms. This vulnerability allows malicious actors to remotely access PTZ information and send unauthorized commands, potentially compromising the device's functionality and the privacy of monitored areas.
Affected Version(s)
GV-LPC2011/LPC2211 1.13
GV-LPC2011/LPC2211 1.14
References
CVSS V3.1
Score:
9.4
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University
