ZeroHour

CVE-2026-88272

niche

Command Injection in GeoVision GV-LPC2211 License Plate Camera

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

GeoVision's GV-LPC2211 license plate capture camera, running firmware V1.13, is vulnerable to OS command injection (CWE-78): an administrator can create a stored username containing shell metacharacters, and when that stored username is later deleted the firmware passes it to a system shell without sanitization. Commands embedded in the username are then executed with root privileges, giving whoever controls that username field full control over the camera (the CVSS confidentiality, integrity and availability impacts are all rated high). Because the vulnerability requires high privileges (CVSS PR:H), exploitation needs an attacker who already holds administrator access to the camera — for example via a compromised, shared, or weakly protected admin account — making this effectively an administrator-to-root escalation rather than an unauthenticated remote compromise. Affected organizations are those running the GV-LPC2211 on firmware V1.13; the available data does not state whether other firmware versions are also affected. No public proof of concept, no CISA KEV listing, and no known reports of in-the-wild exploitation exist at this time.

What to do: Inventory GeoVision GV-LPC2211 devices and record running firmware versions; update to the latest firmware published for this model, checking GeoVision's advisory or download page for a patched release, since no specific fixed version is given in the available data. As an interim mitigation, avoid creating administrator usernames containing shell metacharacters (e.g., ;, |, &, $) and review stored usernames for such characters before deleting them. Restrict the camera's admin interface to trusted management networks and monitor for vendor advisories.

Affected
GeoVision GV-LPC2211 license plate capture camera (IP camera)V1.13 (firmware reported affected; whether other versions are affected is not specified in the available data)
Estimated exposure
nichelikely on the order of thousands of deployed units worldwide (estimate; no public install counts for this model) — Estimated from deployment patterns: the GV-LPC2211 is a single specialized license-plate-capture camera model installed per lane or gate at parking facilities, checkpoints and similar sites rather than a mass-market product, and no public…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled username containing shell metacharacters to be executed as arbitrary root commands when the stored username is later deleted.

Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.