Skip to content
CVSS 8.6 · HIGH

CVE-2026-42365

A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. An attacker can bruteforce session cookies to trigger this vulnerability.

View on NVD

Analysis

This CVE affects specific GeoVision license plate recognition camera firmware. It is niche hardware for physical surveillance and does not impact the software development stacks, Linux servers, or common SaaS tools targeted by this community.

Severity

Score: 8.6(HIGH)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: NONE
A: NONE
Weakness (CWE): CWE-341

EPSS

Probability of exploitation (next 30 days): 0.0006 (0.1%)
Percentile: 19.5%
EPSS: 2026-05-06

Affects

geovision:gv-lpc2011_firmwaregeovision:gv-lpc2011geovision:gv-lpc2211_firmwaregeovision:gv-lpc2211

Technical description

A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. An attacker can bruteforce session cookies to trigger this vulnerability.

Published: 5/4/2026, 1:16:03 AM
Last modified: 5/5/2026, 2:44:42 AM

References

HomeEventsBlogResourcesTeam