CVE-2026-88272
nicheCommand Injection in GeoVision GV-LPC2211 License Plate Camera
GeoVision's GV-LPC2211 license plate capture camera, running firmware V1.13, is vulnerable to OS command injection (CWE-78): an administrator can create a stored username containing shell metacharacters, and when that stored username is later deleted the firmware passes it to a system shell without sanitization. Commands embedded in the username are then executed with root privileges, giving whoever controls that username field full control over the camera (the CVSS confidentiality, integrity and availability impacts are all rated high). Because the vulnerability requires high privileges (CVSS PR:H), exploitation needs an attacker who already holds administrator access to the camera — for example via a compromised, shared, or weakly protected admin account — making this effectively an administrator-to-root escalation rather than an unauthenticated remote compromise. Affected organizations are those running the GV-LPC2211 on firmware V1.13; the available data does not state whether other firmware versions are also affected. No public proof of concept, no CISA KEV listing, and no known reports of in-the-wild exploitation exist at this time.
What to do: Inventory GeoVision GV-LPC2211 devices and record running firmware versions; update to the latest firmware published for this model, checking GeoVision's advisory or download page for a patched release, since no specific fixed version is given in the available data. As an interim mitigation, avoid creating administrator usernames containing shell metacharacters (e.g., ;, |, &, $) and review stored usernames for such characters before deleting them. Restrict the camera's admin interface to trusted management networks and monitor for vendor advisories.
| GeoVision GV-LPC2211 license plate capture camera (IP camera) | V1.13 (firmware reported affected; whether other versions are affected is not specified in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled username containing shell metacharacters to be executed as arbitrary root commands when the stored username is later deleted.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.