CyberRota Analysis
AI-GeneratedGeoVision GV-LPC2211 V1.13 is vulnerable due to inadequate restrictions on the filename parameter in BKDownloadLink.cgi, enabling authenticated remote users to access arbitrary files on the server. This flaw could lead to unauthorized exposure of sensitive information, potentially compromising system integrity. Organizations using this product should prioritize remediation to mitigate the risk of data breaches.
CVE
CVE-2026-88288
Severity
MEDIUM
CVSS
6.5
EPSS
0.37%
Original NVD Description
GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a remote user with valid web credentials to read arbitrary files accessible to the root-run web service.