Description
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless SSID containing shell syntax to execute arbitrary commands as root.
Published: 2026-09-10
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary command execution as root (remote code execution)
Action: Apply Patch
AI Analysis

Impact

GeoVision GV-LPC2211 V1.13 contains a command‑injection vulnerability that allows an administrator to embed shell syntax within the wireless SSID. The device parses the SSID as a system command and executes it with root privileges, enabling arbitrary code execution. This exposure can be used to read, modify, or delete device data, jeopardizing confidentiality, integrity, and availability. The flaw is classified as CWE-78: Improper Output Neutralization for System or OS Commands.

Affected Systems

The vulnerability affects GeoVision Inc.’s GV‑LPC2211 wireless controller, with known susceptibility in firmware releases 1.13 and 1.14 based on the CPE records. Platforms running these firmware versions should check their current build and apply updates if available.

Risk and Exploitability

With a CVSS score of 7.2 the risk is high. The EPSS score is unavailable and the flaw is not currently listed in the CISA KEV catalog, indicating limited public exploitation to date. Exploitation requires the ability to set or modify the SSID, typically through administrative privileges. An attacker who can inject shell syntax into the SSID can achieve full root-level compromise of the device and potentially the network it serves.

Generated by OpenCVE AI on September 10, 2026 at 09:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the GV‑LPC2211 firmware to the latest release that removes the SSID command‑injection flaw.
  • If a newer firmware is not available, disable WAN‑side SSID configuration or restrict the SSID field to a safe character set (e.g., alphanumeric, hyphen, underscore) to eliminate injection possibilities.
  • Ensure that only authenticated administrators can change SSID settings and enforce strong authentication controls such as role‑based access and two‑factor authentication on the device’s management interface.

Generated by OpenCVE AI on September 10, 2026 at 09:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless SSID containing shell syntax to execute arbitrary commands as root.
Title GV-LPC2011/LPC2211 - Wireless SSID Command Injection
First Time appeared Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211
Weaknesses CWE-78
CPEs cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*
Vendors & Products Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Geovision Inc. Gv-lpc2011 Lpc2211
cve-icon MITRE

Status: PUBLISHED

Assigner: GV

Published:

Updated: 2026-09-10T15:49:07.020Z

Reserved: 2026-09-10T02:56:02.025Z

Link: CVE-2026-88274

cve-icon Vulnrichment

Updated: 2026-09-10T15:49:03.331Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T09:17:04.343

Modified: 2026-09-10T16:18:09.153

Link: CVE-2026-88274

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T09:30:10Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')