Impact
The vulnerability resides in the GeoVision GV‑LPC2011/LPC2211 firmware version 1.13, where an administrator‑controlled WPA‑PSK field accepts shell syntax. When a wireless configuration is applied, the embedded shell commands are executed with root privileges. This constitutes an OS command injection flaw (CWE‑78) that can lead to full system compromise if the attacker can supply the WPA‑PSK value.
Affected Systems
The affected product is the GeoVision GV‑LPC2011/LPC2211 wireless controller, specifically firmware version 1.13. Administrators or users with access to the wireless configuration interface of that device are impacted. Versions beyond 1.13 are not listed as vulnerable.
Risk and Exploitability
The CVSS score of 7.2 classifies this as a high severity issue. The EPSS score is not available, and it is not currently listed in CISA KEV. Exploitation requires the ability to modify the WPA‑PSK value via the device’s administrative interface, implying a local or privileged attack vector. The consequences are significant: an attacker who can gain administrative control can execute arbitrary commands as root, compromising the entire device and potentially the associated network. The lack of a publicly disclosed exploit does not diminish the risk posed by the high severity and the easy injection vector.
OpenCVE Enrichment