CVE-2026-42368Disclosure(geovision / gv-lpc2011)

LOWCVSS 9.9 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch geovision gv-lpc2011 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to execute priviledged operation. An attacker can visit a webpage to trigger this vulnerability.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-266

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gv-lpc2011
  • gv-lpc2011_firmware
  • gv-lpc2211
  • gv-lpc2211_firmware

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-05-13); latest day: 3
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
gv-lpc2011gv-lpc2011_firmwaregv-lpc2211gv-lpc2211_firmware

2 versions affected across 4 products

Deep dive

Activity timeline7 mentions / 3d
01223Mentions · 2026-05-13: 3Mentions · 2026-05-15: 1Mentions · 2026-06-02: 3Patch / Workaround · 2026-05-15: 1Technical Details · 2026-05-13: 2Technical Details · 2026-05-15: 1Technical Details · 2026-06-02: 305-1305-1506-02
Signal classification2 categories
Disclosure
571.4%
General
228.6%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-05-133
Disclosure1General2
2026-05-151
Disclosure1
2026-06-023
Disclosure3
Full discourse7 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    GeoVision's LPC2011 and LPC2211 network devices (version 1.10) expose a critical, unauthenticated privilege escalation flaw (CVE-2026-42368, CVSS 9.9) that allows attackers to execute privileged operations via specially crafted HTTP requests. No patch exists. Surveillance…

    Post summary

    GeoVision LPC2011 and LPC2211 devices (v1.10) have a CVE‑2026‑42368 unauthenticated privilege escalation flaw with CVSS 9.9, exploitable through crafted HTTP requests; no patch is currently available.

    1000026
    238 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Surveillance System That Became the Backdoor: GeoVision LPC2011/2211 CVSS 9.9 Privilege Escalation (CVE-2026-42368). GeoVision's LPC2011 and LPC2211 network devices version 1.10 expose a critical, unauthenticated privilege escalation flaw CVE-2026-42368, CVSS 9.9 that…

    Post summary

    The text announces a high‑severity unauthenticated privilege‑escalation flaw (CVE‑2026‑42368) in GeoVision LPC2011/LPC2211 devices, providing its CVSS score and description but no PoC, exploit, or patch details.

    1000031
    238 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    On May 4, 2026, security researchers disclosed CVE-2026-42368 affecting GeoVision's LPC2011 and LPC2211 surveillance system management devices. The vulnerability resides in the Web Interface functionality and carries a severity rating of 9.9 (Critical) on the CVSS scale.

    Post summary

    Researchers announced CVE‑2026‑42368, a critical Web Interface vulnerability in GeoVision LPC devices, despite no PoC, exploit, patch, or active exploitation details being provided.

    1000025
    238 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-42368 CVSS: 9.9 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10.

    Post summary

    A critical privilege escalation flaw (CVE‑2026‑42368) was identified in GeoVision LPC2011/LPC2211 1.10’s web interface; the advisory notes severity but provides no PoC, exploit, or patch information.

    1000029
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVSS 9.9 CRITICAL · CVE-2026-42368 · 9.9 → 1.10 CVE: CVE-2026-42368 CVSS: 9.9 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text merely notes CVE‑2026‑42368 with a CVSS 9.9 critical score, providing no further exploitation or mitigation details.

    1000036
    210 followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    A critical privilege escalation flaw (CVE-2026-42368) impacts GeoVision LPC2011/LPC2211 Web Interface. SMBs using these systems should prioritize updates to prevent unauthorized access and protect sensitive operations. #Cybersecurity

    Post summary

    A critical privilege escalation vulnerability (CVE‑2026‑42368) has been disclosed affecting GeoVision LPC2011/LPC2211 web interfaces; SMBs should promptly update to prevent unauthorized access.

    0000044
    80 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-42368-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The text provides only a link to an advisory and hashtags, with no additional information about the CVE.

    0000023
    210 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
HWgeovisiongv-lpc2011---
OSgeovisiongv-lpc2011_firmware1.10--
HWgeovisiongv-lpc2211---
OSgeovisiongv-lpc2211_firmware1.10--

Explore more