CVE-2026-88277
nicheAuthenticated ONVIF Command Injection (Root RCE) in GeoVision GV-LPC2211 Camera
CVE-2026-88277 is an OS command injection flaw (CWE-78) in the ONVIF interface of the GeoVision GV-LPC2211 license plate recognition camera, confirmed in firmware V1.13. An attacker with valid low-privilege ONVIF credentials can embed shell commands in the ConsumerReference.Address field (used for ONVIF event subscription), which the camera passes to a system shell without sanitization. Because the injected commands run as root, a successful attack gives full control of the camera, including access to video, configuration and stored credentials, and a foothold for pivoting into the surrounding network. Any GV-LPC2211 running V1.13 with ONVIF enabled and at least one ONVIF account is affected; the available data does not state whether other firmware versions are affected. There are no reports of in-the-wild exploitation, no public proof-of-concept, and the CVE is not in CISA KEV, so current risk stems from the flaw's availability rather than observed attacks.
What to do: Check GV-LPC2211 firmware versions and upgrade to the latest release from GeoVision once a patched build is published (no fixed version number is provided in the available data). Until then, keep the camera's ONVIF service off the public internet, restrict ONVIF accounts to trusted users and rotate shared credentials, and review device logs for requests to the ONVIF event service containing unusual ConsumerReference.Address values.
| GeoVision GV-LPC2211 license plate recognition camera | V1.13 (only this version is named in the advisory; other versions not specified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
GeoVision GV-LPC2211 V1.13 allows an authenticated ONVIF user to inject shell commands through ConsumerReference.Address and execute arbitrary commands as root.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.