securityonline.info 11 Sept 2026, 01:40 UTC

GeoVision Cameras Expose Root Access Through Critical Flaws

GeoVision Cameras Expose Root Access Through Critical Flaws
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

GEOVISION has issued a major security advisory detailing twenty-three vulnerabilities across its license plate recognition cameras, affecting GV-LPC2011 and GV-LPC2211 models running firmware 1.13 or earlier (and pre-test 1.14). The flaws span seven CVEs, with the most severe being CVE-2026-88285 (CVSSv3 9.4, CWE-306). The advisory states that there is no confirmed active exploitation or public PoCs at this time.

The issues enable authentication bypass, credential theft or replacement, and remote command execution, potentially giving attackers root access to affected devices. Notably, a Guest user can retrieve plaintext credentials via SSVR and may overwrite device configuration to change the administrator password.

Operational impact could be significant: compromised cameras might intercept sensitive video feeds, serve as internal pivot points within networks, or disrupt traffic monitoring and vehicle-recognition records. The vulnerabilities affect the GV-LPC2011 and GV-LPC2211 families, with firmware 1.13 and earlier (and pre-test 1.14) implicated; GeoVision notes that all issues have been addressed in firmware version 1.14.

In response, administrators are advised to apply the latest firmware immediately, segregate cameras on dedicated VLANs, and restrict administrative web access to trusted internal IPs. No active exploits are confirmed, but rapid patching and network segmentation are recommended to mitigate potential risk.

View full article

Article by CyberSIXT