Improper Management of PTZ Connection State in GeoVision Camera
CVE-2026-88286
7.5HIGH
What is CVE-2026-88286?
The GeoVision GV-LPC2211 camera version V1.13 has a vulnerability that improperly manages the state of the PTZ (Pan-Tilt-Zoom) connection. This flaw can be exploited by an unauthenticated remote client, enabling them to block the accept loop, effectively preventing new PTZ connections. Such an exploit could lead to significant disruption in the functionality of the camera system, making it crucial for users to apply necessary updates and security measures to mitigate potential risks.
Affected Version(s)
GV-LPC2011/LPC2211 1.13
GV-LPC2011/LPC2211 1.14
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University
