No advisories yet.
Solution
GeoVision GV-LPC2011/LPC2211 V1.12-260330 has patched the reported vulnerability. The user may visit GeoVision website or contact GeoVision Support team for firmware update.
Workaround
No workaround given by the vendor.
Mon, 04 May 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. Reflected XXS via the error message for requesting non-existing page. | |
| Title | GeoVision LPC2011/LPC2211 Web Interface / ssi.cgi reflected cross-site scripting (XSS) vulnerabilities | |
| First Time appeared |
Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211 |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:v1.10:*:linux:*:*:*:*:* cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:v1.20:*:linux:*:*:*:*:* |
|
| Vendors & Products |
Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GV
Published:
Updated: 2026-05-04T00:43:05.061Z
Reserved: 2026-04-28T22:53:06.123Z
Link: CVE-2026-7371
No data.
Status : Received
Published: 2026-05-04T01:16:04.590
Modified: 2026-05-04T01:16:04.590
Link: CVE-2026-7371
No data.
OpenCVE Enrichment
Updated: 2026-05-04T03:00:11Z