GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens in unauthenticated ONVIF WS-Discovery Probe requests, allowing a remote attacker to corrupt stack control state and crash the discovery process.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-88287 is a stack buffer overflow vulnerability (CWE-121) in GeoVision GV-LPC2211 V1.13 that exploits unauthenticated ONVIF WS-Discovery Probe requests. The vulnerability stems from insufficient bounds checking on Scopes tokens, allowing remote attackers to craft malicious discovery requests that corrupt stack memory and crash the device's discovery process. This affects organizations deploying GeoVision IP cameras in security surveillance infrastructure, where discovery mechanisms are often exposed on network segments or accessible to unauthenticated clients. The lack of authentication requirement significantly lowers the barrier to exploitation, making this a network-reachable denial-of-service vector that can disrupt camera availability and monitoring capabilities.
While this CVE does not map to specific MITRE ATT&CK techniques, Casky.ai's 754 security skills would detect the attack patterns through behavioral analysis of malformed ONVIF requests and stack manipulation attempts. Although zero Casky skills currently match this exact vulnerability, practitioners using Casky would identify related defensive capabilities around protocol fuzzing detection, memory corruption indicators, and network discovery anomalies. A practitioner's findings would highlight unauthenticated WS-Discovery traffic patterns, abnormal Scope token structures, and device crash events—enabling network defenders to implement discovery request filtering, rate limiting on ONVIF endpoints, and segmentation of camera infrastructure from untrusted network zones before exploitation occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-88287. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation