CVE-2026-42365
A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. An attacker can bruteforce session cookies to trigger this vulnerability.
View on NVDAnalysis
This CVE affects specific GeoVision license plate recognition camera firmware. It is niche hardware for physical surveillance and does not impact the software development stacks, Linux servers, or common SaaS tools targeted by this community.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:NCWE-341EPSS
Affects
geovision:gv-lpc2011_firmwaregeovision:gv-lpc2011geovision:gv-lpc2211_firmwaregeovision:gv-lpc2211Technical description
A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. An attacker can bruteforce session cookies to trigger this vulnerability.