ZeroHour

CVE-2026-88273

niche

Post-auth root command injection in GeoVision GV-LPC2211 via PPPoE username

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-88273 is an OS command injection flaw (CWE-78) in the GeoVision GV-LPC2211 license plate capture camera: an administrator-supplied PPPoE username is inserted into a sourced shell configuration assignment without escaping. When that configuration file is sourced by a shell running as root, shell metacharacters in the username break out of the assignment and execute arbitrary attacker-supplied commands with root privileges. Because the flaw requires administrator privileges (CVSS 3.1 PR:H, score 7.2), an attacker first needs admin access to the camera — for example via weak, default, or reused credentials — and then gains full root control of the device, enabling persistence, theft of configuration/credentials, and pivoting into the surrounding surveillance network. Affected deployments are GV-LPC2211 units running firmware V1.13; other version ranges are not specified in the available data. There is currently no evidence of exploitation: the flaw is not in CISA KEV and no public proof-of-concept is known.

What to do: Inventory your GV-LPC2211 fleet and identify units on firmware V1.13; until GeoVision publishes a fixed firmware, avoid configuring PPPoE on affected units (use static IP or DHCP instead) — devices that do not use PPPoE are unlikely to be triggerable through this path. Restrict administrative access to the cameras' management interfaces, enforce strong admin credentials, and avoid exposing management ports to the internet. Monitor the GeoVision support/download portal for a patched firmware release and apply it when available.

Affected
GeoVision GV-LPC2211 license plate capture camerafirmware V1.13 (confirmed affected per the advisory; earlier/later versions not specified in the available data)
Estimated exposure
nicheunknown; plausibly on the order of thousands of deployed units — No public install-base, market-share, or internet-exposure scan data is available for this specific model, which is a specialized license-plate-capture camera deployed mainly at parking, tolling, and access-control sites rather than as a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a sourced shell configuration assignment and execute arbitrary commands as root.

Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.