SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-88278

CRITICAL · CVSS 9.8 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

GeoVision GV-LPC2211 V1.13 is vulnerable due to inadequate enforcement of WS-Security UsernameToken freshness and nonce reuse protection, which permits attackers to replay captured PasswordDigest tokens during ONVIF operations. This critical vulnerability (CVSS 9.8) can lead to unauthorized access and control over the affected device. Organizations utilizing this product should prioritize immediate remediation to mitigate potential exploitation risks.

CVE
CVE-2026-88278
Severity
CRITICAL
CVSS
9.8
EPSS
0.27%

Original NVD Description

GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations.