Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.geovision.com.tw/cyber_security.php |
|
Thu, 10 Sep 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a remote user with valid web credentials to read arbitrary files accessible to the root-run web service. | |
| Title | GV-LPC2011/LPC2211 - Arbitrary File Read Through BKDownloadLink.cgi Symlink Creation | |
| First Time appeared |
Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211 |
|
| Weaknesses | CWE-36 | |
| CPEs | cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:* cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:* |
|
| Vendors & Products |
Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GV
Published:
Updated: 2026-09-10T08:25:21.248Z
Reserved: 2026-09-10T02:56:06.154Z
Link: CVE-2026-88288
No data.
Status : Received
Published: 2026-09-10T09:17:05.893
Modified: 2026-09-10T09:17:05.893
Link: CVE-2026-88288
No data.
OpenCVE Enrichment
Updated: 2026-09-10T09:45:07Z
