CVE-2026-88282
nicheRoot Command Injection via FTP Username in GeoVision GV-LPC2211
GeoVision's GV-LPC2211 license plate capture camera running firmware V1.13 fails to sanitize the FTP username, so shell metacharacters entered in that field are later interpreted as operating-system commands. The injection triggers when the device processes a subsequent FTP-account update, at which point the metacharacters in the stored username are executed with root privileges. Because the injected code runs as root, an attacker who can set or has compromised an administrator account gains complete control of the camera, including full read/write access and a potential foothold on the surveillance network. Only GV-LPC2211 units running V1.13 are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the flaw is not yet listed in CISA's Known Exploited Vulnerabilities catalog.
What to do: Monitor GeoVision for a firmware release fixing this issue and upgrade the GV-LPC2211 beyond V1.13 when it becomes available. As an interim mitigation, avoid FTP account usernames containing shell metacharacters (such as ;, |, &, $, backticks or spaces), limit administrator access to the camera, and keep the device's management interface off the public internet.
| GeoVision GV-LPC2211 (license plate capture camera) | V1.13 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled FTP username containing shell metacharacters to be executed as arbitrary root commands during a subsequent FTP-account update.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.