Description
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a sourced shell configuration assignment and execute arbitrary commands as root.
Published: 2026-09-10
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is a command injection flaw in the PPPoE username handling of GeoVision GV‑LPC2011/LPC2211 firmware version 1.13. An attacker with the ability to set or modify the username can cause the firmware to execute arbitrary shell commands with root privileges. This gives the attacker full control over the device, enabling data theft, configuration tampering, or further lateral movement in the network.

Affected Systems

Affected systems are devices running GeoVision Inc.'s GV‑LPC2011/LPC2211 firmware version 1.13, and the same family of devices identified by the vendor as 1.14 may share the same code path. The product is a PPPoE‑capable network device provided by GeoVision.

Risk and Exploitability

The CVSS score of 7.2 categorizes this flaw as high severity, and while EPSS data is not available, the lack of a KEV listing does not diminish the intrinsic risk. An attacker who can configure the PPPoE username, as an authenticated admin, can achieve remote code execution. The required access is administrative over PPPoE or local configuration interfaces, so an authenticated attacker could exploit this vulnerability without the need for external network-level access.

Generated by OpenCVE AI on September 10, 2026 at 09:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a firmware update that removes the command injection flaw in PPPoE username processing.
  • If an update is unavailable, restrict PPPoE username configuration to trusted values or disable the feature entirely.
  • Apply the principle of least privilege by removing unnecessary administrative accounts and limiting network access to the device.
  • Monitor the device's system logs for unexpected command execution or privilege escalations.

Generated by OpenCVE AI on September 10, 2026 at 09:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a sourced shell configuration assignment and execute arbitrary commands as root.
Title GV-LPC2011/LPC2211 - PPPoE Username Shell-Configuration Command Injection
First Time appeared Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211
Weaknesses CWE-78
CPEs cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*
Vendors & Products Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Geovision Inc. Gv-lpc2011 Lpc2211
cve-icon MITRE

Status: PUBLISHED

Assigner: GV

Published:

Updated: 2026-09-10T15:52:25.823Z

Reserved: 2026-09-10T02:56:02.025Z

Link: CVE-2026-88273

cve-icon Vulnrichment

Updated: 2026-09-10T15:52:20.160Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T09:17:04.230

Modified: 2026-09-10T16:18:09.050

Link: CVE-2026-88273

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T09:30:10Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')