CVE-2026-42365
A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. An attacker can bruteforce session cookies to trigger this vulnerability.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
- EPSS probability
- 0.34%
- CWE
- CWE-341
- Published
- 2026-05-04
- Last modified
- 2026-06-15
Affected products
- GeoVision Inc. GV-LPC2011/LPC2211
- GeoVision Inc. GV-LPC2011/LPC2211
Weakness type
Related vulnerabilities
- CVE-2026-19565 — Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey
- CVE-2026-15571 — Keycloak-services: keycloak-services: predictable account-linking hash enables account takeover via malicious oidc client
- CVE-2025-40780 — Cache poisoning due to weak PRNG
- CVE-2025-42925 — Predictable Object Identifier vulnerability in SAP NetWeaver AS Java (IIOP Service)
- CVE-2024-10141 — jsbroks COCO Annotator Session predictable state
- CVE-2023-49259 — Bruteforcing authentication cookie for a given user
- CVE-2021-4277 — fredsmith utils Filename screenshot_sync predictable state
- CVE-2020-5365 — Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability. The...