GeoVision Inc. Vulnerabilities and Affected Products
Vulnerabilities associated with GV-LPC2011/LPC2211.
Products
Clear product- GeoWebPlayer18 vulnerabilities
- GV-LPCLPC2011/221110 vulnerabilities
- GV-I/O Box 4E8 vulnerabilities
- GV-LPC2011/LPC22116 vulnerabilities
- GV-IP Device Utility3 vulnerabilities
- GV-VMS V20.0.23 vulnerabilities
- ASManager1 vulnerability
- GeoVision1 vulnerability
- GeoVision embedded IP devices1 vulnerability
- GV-AS1620 (AS-Manager)1 vulnerability
- GV-AS1620 (GV-Cloud)1 vulnerability
- GV-ASManager1 vulnerability
- GV-BX15001 vulnerability
- GV-MFD15011 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-42368CRITICAL | GeoVision LPC2011/LPC2211 Web Interface privilege escalation vulnerabilityA privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to execute priviledged operation. An attacker can visit a webpage to trigger this vulnerability. CWE-266May 4, 2026 | CVSS9.9v3.1 | EPSS0.363% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-42367MEDIUM | GeoVision LPC2011/LPC2211 Web Interface / ssi.cgi privilege escalation vulnerability via leak of Administrator credentialsA privilege escalation vulnerability exists in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to credentials leak. An attacker can visit a webpage to trigger this vulnerability. CWE-522May 4, 2026 | CVSS6.5v3.1 | EPSS0.283% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-7371HIGH | GeoVision LPC2011/LPC2211 Web Interface / ssi.cgi reflected cross-site scripting (XSS) vulnerabilitiesMultiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. Reflected XXS via the error message for requesting non-existing page. CWE-79May 4, 2026 | CVSS7.4v3.1 | EPSS0.205% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-42366HIGH | GeoVision LPC2011/LPC2211 Web Interface / ssi.cgi reflected cross-site scripting (XSS) vulnerabilitiesMultiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. CWE-79May 4, 2026 | CVSS7.4v3.1 | EPSS0.205% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-42365HIGH | GeoVision LPC2011/LPC2211 Web Interface guessable session cookie vulnerabilityA guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. An attacker can bruteforce session cookies to trigger this vulnerability. CWE-341May 4, 2026 | CVSS8.6v3.1 | EPSS0.343% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-42364CRITICAL | GeoVision LPC2011/LPC2211 Web Interface / DdnsSetting.cgi OS command injection vulnerabilityAn os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An attacker can modify a configuration value to trigger this vulnerability. CWE-78May 4, 2026 | CVSS9.9v3.1 | EPSS1.68% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |