CVE-2026-88276
nicheRoot Command Injection via WEP Key Input in GeoVision GV-LPC2211 Camera
GeoVision's GV-LPC2211 license-plate-recognition camera running firmware V1.13 is vulnerable to OS command injection (CWE-78) in its handling of WEP key values, which are passed into a shell command without sanitization. An authenticated administrator (or anyone who controls the admin account) can enter a WEP key containing shell metacharacters, causing the injected commands to execute as root on the device. Because execution is as root, a successful attacker gains full control of the camera's operating system, which can be used to tamper with or exfiltrate video, establish persistence, and pivot into the surrounding surveillance network. The flaw is rated CVSS 3.1 7.2 (high) with network access, low complexity, and high privileges required, so exploitation depends on an attacker already having administrative access, for example via stolen, reused, or default admin credentials. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known at this time.
What to do: Inventory GV-LPC2211 deployments and check whether units run firmware V1.13, then upgrade to GeoVision's patched firmware once the vendor publishes a fix (no fixed version is listed in the available data). Until then, restrict administrator access to the camera's management interface, avoid exposing it to the internet, and protect admin credentials, since exploitation requires administrator privileges. Also review existing WEP key configuration values for shell metacharacters, which could indicate prior command execution.
| GeoVision GV-LPC2211 (license plate recognition camera) | V1.13 firmware; no other version ranges are specified in the available data |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
GeoVision GV-LPC2211 V1.13 allows administrator-controlled WEP key values containing shell syntax to execute arbitrary commands as root.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.