GeoVision released a major security advisory addressing twenty-three flaws across its license plate recognition cameras on September 10, 2026. These severe GeoVision camera vulnerabilities allow attackers to bypass authentication, hijack administrative accounts, and execute system commands. Currently, security teams have confirmed no active exploitation or public proof-of-concept exploits for these issues.
- Total: 7 CVEs
- Severity: 1 Critical · 2 High · 4 Medium
- Actively exploited: None confirmed
- Highest severity: 9.4 (Critical · CVSSv3) — CVE-2026-88285
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-88285 | 9.4 | CWE-306 | 1.14 | Not exploited |
| CVE-2026-88271 | 8.8 | CWE-862 | 1.14 | Not exploited |
| CVE-2026-88277 | 8.8 | CWE-78 | 1.14 | Not exploited |
| CVE-2026-88268 | 6.5 | CWE-121 | 1.14 | Not exploited |
| CVE-2026-88269 | 6.5 | CWE-862 | 1.14 | Not exploited |
| CVE-2026-88270 | 6.5 | CWE-862 | 1.14 | Not exploited |
| CVE-2026-88288 | 6.5 | CWE-36 | 1.14 | Not exploited |
Why This Threat Matters
Industry analysts estimate that transport operators and security facilities deploy thousands of GeoVision surveillance cameras worldwide. Therefore, vulnerabilities in edge surveillance cameras threaten physical security perimeters. If attackers compromise these devices, they can intercept sensitive video feeds. Furthermore, threat actors can use compromised camera systems as internal pivot points. Intruders can also disable traffic monitoring feeds or alter vehicle recognition records. Consequently, unpatched GeoVision camera vulnerabilities expose entire corporate subnets to unauthorized intrusions.
How the Attacks Work
Authentication Bypass and Credential Theft
Multiple flaws reside within the camera video streaming and management interfaces. Specifically, low-privileged users can access sensitive internal settings. The advisory warns, “A Guest user can retrieve persistent device configuration containing plaintext administrative and user credentials through SSVR.” Additionally, another flaw allows unauthorized password replacement. The vendor notes, “A Guest user can overwrite device configuration and replace the administrator password through SSVR.”
Command Injection and Service Exposure
Attackers can also achieve root-level code execution on affected devices. For instance, multiple parameters fail to sanitize shell metacharacters before executing commands. Meanwhile, other flaws expose hardware interfaces over the network. The advisory states, “A network-accessible PTZ control service is exposed without authentication, allowing remote clients to retrieve PTZ information and issue PTZ or raw serial commands.” Moreover, web services allow authenticated users to read arbitrary files from storage.
Affected Versions
These flaws impact the GV-LPC2011 and GV-LPC2211 camera models running firmware version 1.13 or earlier. Additionally, the vulnerabilities affect pre-test firmware version 1.14. Researchers have identified no active in-the-wild exploitation. Public proof-of-concept exploits do not exist at this time.
Patch and Mitigation Steps
Administrators must deploy firmware updates immediately to protect their surveillance networks. GeoVision resolved all reported issues in firmware release version 1.14. Therefore, operators should visit the GeoVision cybersecurity page to download the latest firmware. Teams should also isolate surveillance cameras on dedicated virtual local area networks. Finally, administrators must restrict administrative web access to trusted internal IP addresses.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!