Impact
GeoVision GV-LPC2211 V1.13 contains a command‑injection vulnerability that allows an administrator to embed shell syntax within the wireless SSID. The device parses the SSID as a system command and executes it with root privileges, enabling arbitrary code execution. This exposure can be used to read, modify, or delete device data, jeopardizing confidentiality, integrity, and availability. The flaw is classified as CWE-78: Improper Output Neutralization for System or OS Commands.
Affected Systems
The vulnerability affects GeoVision Inc.’s GV‑LPC2211 wireless controller, with known susceptibility in firmware releases 1.13 and 1.14 based on the CPE records. Platforms running these firmware versions should check their current build and apply updates if available.
Risk and Exploitability
With a CVSS score of 7.2 the risk is high. The EPSS score is unavailable and the flaw is not currently listed in the CISA KEV catalog, indicating limited public exploitation to date. Exploitation requires the ability to set or modify the SSID, typically through administrative privileges. An attacker who can inject shell syntax into the SSID can achieve full root-level compromise of the device and potentially the network it serves.
OpenCVE Enrichment