ZeroHour

CVE-2026-88277

niche

Authenticated ONVIF Command Injection (Root RCE) in GeoVision GV-LPC2211 Camera

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-88277 is an OS command injection flaw (CWE-78) in the ONVIF interface of the GeoVision GV-LPC2211 license plate recognition camera, confirmed in firmware V1.13. An attacker with valid low-privilege ONVIF credentials can embed shell commands in the ConsumerReference.Address field (used for ONVIF event subscription), which the camera passes to a system shell without sanitization. Because the injected commands run as root, a successful attack gives full control of the camera, including access to video, configuration and stored credentials, and a foothold for pivoting into the surrounding network. Any GV-LPC2211 running V1.13 with ONVIF enabled and at least one ONVIF account is affected; the available data does not state whether other firmware versions are affected. There are no reports of in-the-wild exploitation, no public proof-of-concept, and the CVE is not in CISA KEV, so current risk stems from the flaw's availability rather than observed attacks.

What to do: Check GV-LPC2211 firmware versions and upgrade to the latest release from GeoVision once a patched build is published (no fixed version number is provided in the available data). Until then, keep the camera's ONVIF service off the public internet, restrict ONVIF accounts to trusted users and rotate shared credentials, and review device logs for requests to the ONVIF event service containing unusual ConsumerReference.Address values.

Affected
GeoVision GV-LPC2211 license plate recognition cameraV1.13 (only this version is named in the advisory; other versions not specified)
Estimated exposure
nichelikely in the low thousands of installed units worldwide (single specialized camera model; ONVIF-authentication prerequisite shrinks the exploitable set… — The GV-LPC2211 is a single license-plate-recognition camera model from a mid-tier vendor, typically deployed at parking and traffic sites, and no public install counts or internet-exposure scans are available, so the figure is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

GeoVision GV-LPC2211 V1.13 allows an authenticated ONVIF user to inject shell commands through ConsumerReference.Address and execute arbitrary commands as root.

Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.