SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-88288

MEDIUM · CVSS 6.5 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

GeoVision GV-LPC2211 V1.13 is vulnerable due to inadequate restrictions on the filename parameter in BKDownloadLink.cgi, enabling authenticated remote users to access arbitrary files on the server. This flaw could lead to unauthorized exposure of sensitive information, potentially compromising system integrity. Organizations using this product should prioritize remediation to mitigate the risk of data breaches.

CVE
CVE-2026-88288
Severity
MEDIUM
CVSS
6.5
EPSS
0.37%

Original NVD Description

GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a remote user with valid web credentials to read arbitrary files accessible to the root-run web service.