CVE-2026-88273
nichePost-auth root command injection in GeoVision GV-LPC2211 via PPPoE username
CVE-2026-88273 is an OS command injection flaw (CWE-78) in the GeoVision GV-LPC2211 license plate capture camera: an administrator-supplied PPPoE username is inserted into a sourced shell configuration assignment without escaping. When that configuration file is sourced by a shell running as root, shell metacharacters in the username break out of the assignment and execute arbitrary attacker-supplied commands with root privileges. Because the flaw requires administrator privileges (CVSS 3.1 PR:H, score 7.2), an attacker first needs admin access to the camera — for example via weak, default, or reused credentials — and then gains full root control of the device, enabling persistence, theft of configuration/credentials, and pivoting into the surrounding surveillance network. Affected deployments are GV-LPC2211 units running firmware V1.13; other version ranges are not specified in the available data. There is currently no evidence of exploitation: the flaw is not in CISA KEV and no public proof-of-concept is known.
What to do: Inventory your GV-LPC2211 fleet and identify units on firmware V1.13; until GeoVision publishes a fixed firmware, avoid configuring PPPoE on affected units (use static IP or DHCP instead) — devices that do not use PPPoE are unlikely to be triggerable through this path. Restrict administrative access to the cameras' management interfaces, enforce strong admin credentials, and avoid exposing management ports to the internet. Monitor the GeoVision support/download portal for a patched firmware release and apply it when available.
| GeoVision GV-LPC2211 license plate capture camera | firmware V1.13 (confirmed affected per the advisory; earlier/later versions not specified in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a sourced shell configuration assignment and execute arbitrary commands as root.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.