ZeroHour

CVE-2026-88274

niche

OS Command Injection via Wireless SSID in GeoVision GV-LPC2211 Camera

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

GeoVision GV-LPC2211 firmware V1.13 does not sanitize the administrator-configured wireless network name (SSID) before passing it to a shell command, which is an OS command injection flaw (CWE-78). The issue is triggered when an SSID containing shell metacharacters (e.g., ; | $ or backticks) is configured on the device, causing the injected syntax to be executed. Because the flaw runs commands with root privileges and requires high-privilege (administrator) access per the CVSS 7.2 score, an authenticated admin or anyone able to control the SSID value the device accepts gains full root-level command execution on the camera — complete control of the device, its footage and configuration, and a foothold to pivot into the surrounding surveillance network. Affected organizations are those running GeoVision GV-LPC2211 license-plate-capture network cameras on firmware V1.13. There is currently no known public proof-of-concept, the flaw is not in CISA KEV, and no in-the-wild exploitation has been reported.

What to do: Inventory deployments for GV-LPC2211 cameras and check the installed firmware version against V1.13; apply the fixed firmware as soon as GeoVision publishes it (no fixed version is stated in the available data). Until then, restrict administrator access to the devices, avoid configuring wireless SSIDs containing shell metacharacters, and limit the cameras' network exposure; monitor GeoVision's advisory channel for an updated release.

Affected
GeoVision GV-LPC2211 license-plate-capture network cameraFirmware V1.13 confirmed affected; exact affected/fixed version range not specified in available data
Estimated exposure
nichelikely low thousands of deployed units worldwide (single specialized camera model; no public scan or install counts available) — The GV-LPC2211 is a single niche license-plate-capture camera model typically deployed at parking and traffic-monitoring sites rather than at mass scale, and no internet-exposure scan data or install-base figures were provided, so this is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless SSID containing shell syntax to execute arbitrary commands as root.

Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.