GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
GeoVision GV-LPC2211 V1.13 surveillance cameras contain a critical authentication bypass vulnerability (CVE-2026-88278, CVSS 9.8) in their ONVIF implementation. The device fails to validate WS-Security UsernameToken freshness or implement nonce reuse protection, meaning an attacker who captures a PasswordDigest token can replay it indefinitely to gain unauthorized access to camera operations. This affects organizations deploying these IP cameras in security infrastructure, as the vulnerability enables complete compromise of camera control without requiring credential theft or password cracking—only passive network observation. Given the widespread use of GeoVision cameras in enterprise surveillance systems, physical security facilities, and critical infrastructure, this represents a significant risk to organizations relying on ONVIF-compliant devices for access control and monitoring.
While this CVE currently maps to zero Casky skills (indicating limited direct MITRE ATT&CK alignment), practitioners using Casky's extended reasoning capabilities would detect attack patterns associated with Credential Access techniques through network behavior analysis. The platform's 754 mapped security skills would help identify reconnaissance activity (T1592 - Gather Victim Identity Information) as attackers probe for ONVIF endpoints, and T1040 (Traffic Capture) patterns showing repeated identical authentication tokens crossing network boundaries. A practitioner reviewing Casky findings would observe anomalies including: identical PasswordDigest values appearing in multiple ONVIF requests over time, absence of changing nonce values in captured authentication streams, and successful ONVIF method invocations using replayed tokens from earlier sessions. This token reuse signature—particularly the lack of temporal variation—becomes the observable indicator that distinguishes replay attacks from legitimate authentication flows in network telemetry and API logs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-88278. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation