CVE-2026-88285
GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve PTZ information and issue PTZ or raw serial commands.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.4
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
- CWE
- CWE-306
- Published
- 2026-09-10
- Last modified
- 2026-09-10
Affected products
- GeoVision Inc. GV-LPC2011/LPC2211
- GeoVision Inc. GV-LPC2011/LPC2211