CVE-2026-88274
nicheOS Command Injection via Wireless SSID in GeoVision GV-LPC2211 Camera
GeoVision GV-LPC2211 firmware V1.13 does not sanitize the administrator-configured wireless network name (SSID) before passing it to a shell command, which is an OS command injection flaw (CWE-78). The issue is triggered when an SSID containing shell metacharacters (e.g., ; | $ or backticks) is configured on the device, causing the injected syntax to be executed. Because the flaw runs commands with root privileges and requires high-privilege (administrator) access per the CVSS 7.2 score, an authenticated admin or anyone able to control the SSID value the device accepts gains full root-level command execution on the camera — complete control of the device, its footage and configuration, and a foothold to pivot into the surrounding surveillance network. Affected organizations are those running GeoVision GV-LPC2211 license-plate-capture network cameras on firmware V1.13. There is currently no known public proof-of-concept, the flaw is not in CISA KEV, and no in-the-wild exploitation has been reported.
What to do: Inventory deployments for GV-LPC2211 cameras and check the installed firmware version against V1.13; apply the fixed firmware as soon as GeoVision publishes it (no fixed version is stated in the available data). Until then, restrict administrator access to the devices, avoid configuring wireless SSIDs containing shell metacharacters, and limit the cameras' network exposure; monitor GeoVision's advisory channel for an updated release.
| GeoVision GV-LPC2211 license-plate-capture network camera | Firmware V1.13 confirmed affected; exact affected/fixed version range not specified in available data |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless SSID containing shell syntax to execute arbitrary commands as root.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.