Description
A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to execute priviledged operation. An attacker can visit a webpage to trigger this vulnerability.
Problem types
CWE-266 Incorrect privilege assignment
Product status
1.10
1.2
Timeline
| 2026-02-17: | Initial Vendor Contact |
Credits
Philippe Laulheret of Cisco Talos.
Kelly Patterson of Cisco Talos.
Martin Zeiser of Cisco Talos.
References
www.geovision.com.tw/cyber_security.php
https//talosintelligence.com/vulnerability_reports/