Impact
The vulnerability is a command injection flaw in the PPPoE username handling of GeoVision GV‑LPC2011/LPC2211 firmware version 1.13. An attacker with the ability to set or modify the username can cause the firmware to execute arbitrary shell commands with root privileges. This gives the attacker full control over the device, enabling data theft, configuration tampering, or further lateral movement in the network.
Affected Systems
Affected systems are devices running GeoVision Inc.'s GV‑LPC2011/LPC2211 firmware version 1.13, and the same family of devices identified by the vendor as 1.14 may share the same code path. The product is a PPPoE‑capable network device provided by GeoVision.
Risk and Exploitability
The CVSS score of 7.2 categorizes this flaw as high severity, and while EPSS data is not available, the lack of a KEV listing does not diminish the intrinsic risk. An attacker who can configure the PPPoE username, as an authenticated admin, can achieve remote code execution. The required access is administrative over PPPoE or local configuration interfaces, so an authenticated attacker could exploit this vulnerability without the need for external network-level access.
OpenCVE Enrichment