ZeroHour

CVE-2026-88275

niche

Root OS Command Injection via WPA-PSK in GeoVision GV-LPC2211 Wireless Config

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-88275 is an OS command injection flaw (CWE-78) in the wireless configuration handler of the GeoVision GV-LPC2211 license-plate-recognition camera running firmware V1.13. When a wireless configuration is applied, the administrator-supplied WPA-PSK passphrase is passed to a system shell without sanitization, so shell metacharacters in the passphrase are interpreted and any injected commands execute with root privileges. Because the flaw requires high privileges (CVSS PR:H), an attacker needs valid administrator access to the camera - for example via compromised or reused admin credentials, an insider, or chained from another bug - and gains full root-level command execution, meaning complete control of the device, access to its video and configuration, and a foothold for pivoting into the surrounding network. Only the GV-LPC2211 on firmware V1.13 is identified as affected in the available data, and a fixed firmware version is not stated. The issue is not listed in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so there is no confirmed exploitation to date.

What to do: Check the firmware version of any GV-LPC2211 cameras in your fleet; until GeoVision publishes a fixed release (none is specified in the available data), avoid using WPA-PSK passphrases containing shell metacharacters such as $, ;, |, &, backticks, or quotes when applying wireless configuration, and restrict administrator credentials to trusted users with strong, unique passwords. Because exploitation requires administrator privileges, limiting camera management access to a dedicated management VLAN or restricted network segment reduces risk. Monitor GeoVision security advisories for a patched firmware and apply it promptly when released.

Affected
GeoVision GV-LPC2211 (license plate recognition camera) firmwareV1.13 (only version identified as affected; other versions not specified in the available data)
Estimated exposure
nichelikely on the order of thousands to low tens of thousands of units deployed worldwide (single specialized LPR camera model; no public install-base figure) — The GV-LPC2211 is a single, specialized license-plate-recognition camera model sold business-to-business into parking, campus and traffic deployments that typically sit on local networks rather than being internet-exposed; no public…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to execute arbitrary commands as root when wireless configuration is applied.

Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.