ZeroHour

CVE-2026-88276

niche

Root Command Injection via WEP Key Input in GeoVision GV-LPC2211 Camera

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

GeoVision's GV-LPC2211 license-plate-recognition camera running firmware V1.13 is vulnerable to OS command injection (CWE-78) in its handling of WEP key values, which are passed into a shell command without sanitization. An authenticated administrator (or anyone who controls the admin account) can enter a WEP key containing shell metacharacters, causing the injected commands to execute as root on the device. Because execution is as root, a successful attacker gains full control of the camera's operating system, which can be used to tamper with or exfiltrate video, establish persistence, and pivot into the surrounding surveillance network. The flaw is rated CVSS 3.1 7.2 (high) with network access, low complexity, and high privileges required, so exploitation depends on an attacker already having administrative access, for example via stolen, reused, or default admin credentials. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known at this time.

What to do: Inventory GV-LPC2211 deployments and check whether units run firmware V1.13, then upgrade to GeoVision's patched firmware once the vendor publishes a fix (no fixed version is listed in the available data). Until then, restrict administrator access to the camera's management interface, avoid exposing it to the internet, and protect admin credentials, since exploitation requires administrator privileges. Also review existing WEP key configuration values for shell metacharacters, which could indicate prior command execution.

Affected
GeoVision GV-LPC2211 (license plate recognition camera)V1.13 firmware; no other version ranges are specified in the available data
Estimated exposure
nichelikely low thousands of deployed units, with only a minority internet-exposed (estimate; no public scan data for this model) — This is a single, specialized license-plate-recognition camera model; such units are typically deployed at parking entrances, gates, and toll points on local networks rather than exposed to the internet, so the plausibly affected base is a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

GeoVision GV-LPC2211 V1.13 allows administrator-controlled WEP key values containing shell syntax to execute arbitrary commands as root.

Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.