CVE-2026-88278: CWE-294 Authentication bypass by capture-replay in GeoVision Inc. GV-LPCLPC2011/2211
GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations.
AI Analysis
Technical Summary
The vulnerability in GeoVision GV-LPC2211 V1.13 arises from improper enforcement of WS-Security UsernameToken freshness and nonce reuse protections. Specifically, the device does not prevent reuse of a captured PasswordDigest token, enabling an attacker to replay this token to bypass authentication controls for ONVIF operations. This is classified as CWE-294 (Authentication Bypass). No official patch or remediation has been disclosed by the vendor as of the publication date.
Potential Impact
Successful exploitation allows an unauthenticated attacker to bypass authentication mechanisms and perform ONVIF operations with full confidentiality, integrity, and availability impact. This could lead to unauthorized control or manipulation of the affected device.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict network access to the affected device to trusted users only and monitor for suspicious activity related to ONVIF operations.
CVE-2026-88278: CWE-294 Authentication bypass by capture-replay in GeoVision Inc. GV-LPCLPC2011/2211
Description
GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations.
CVSS v3.1
Score 9.8critical
Affected software
pkg:github/geovisioninc/GV-LPCLPC2011-2211Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in GeoVision GV-LPC2211 V1.13 arises from improper enforcement of WS-Security UsernameToken freshness and nonce reuse protections. Specifically, the device does not prevent reuse of a captured PasswordDigest token, enabling an attacker to replay this token to bypass authentication controls for ONVIF operations. This is classified as CWE-294 (Authentication Bypass). No official patch or remediation has been disclosed by the vendor as of the publication date.
Potential Impact
Successful exploitation allows an unauthenticated attacker to bypass authentication mechanisms and perform ONVIF operations with full confidentiality, integrity, and availability impact. This could lead to unauthorized control or manipulation of the affected device.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict network access to the affected device to trusted users only and monitor for suspicious activity related to ONVIF operations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GV
- Date Reserved
- 2026-09-10T02:56:04.082Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6aa26c62acd9273b49cafa28
Added to database: 09/10/2026, 08:37:54 UTC
Last enriched: 09/10/2026, 08:52:34 UTC
Last updated: 09/10/2026, 17:00:16 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.