Impact
The vulnerability in GeoVision GV-LPC2211 allows an administrator-controlled username to contain shell metacharacters that are executed as arbitrary root commands when the stored username is later deleted. This injected code runs with root privileges, giving an attacker the ability to execute any command on the affected device. The flaw is a classic command injection weakness (CWE-78) that can compromise the confidentiality, integrity, and availability of the system.
Affected Systems
GeoVision Inc. products GV-LPC2011/LPC2211, specifically firmware versions 1.13 and 1.14.
Risk and Exploitability
The CVSS score of 7.2 indicates a high potential impact, but the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting an uncertain exploitation likelihood. The attack requires the ability to delete a stored administrator username, implying that an attacker would need privileged or administrator access to the device. If such access is present, the vulnerability can be leveraged to execute arbitrary root commands during the deletion process.
OpenCVE Enrichment