Description
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to execute arbitrary commands as root when wireless configuration is applied.
Published: 2026-09-10
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary command execution with root privileges
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the GeoVision GV‑LPC2011/LPC2211 firmware version 1.13, where an administrator‑controlled WPA‑PSK field accepts shell syntax. When a wireless configuration is applied, the embedded shell commands are executed with root privileges. This constitutes an OS command injection flaw (CWE‑78) that can lead to full system compromise if the attacker can supply the WPA‑PSK value.

Affected Systems

The affected product is the GeoVision GV‑LPC2011/LPC2211 wireless controller, specifically firmware version 1.13. Administrators or users with access to the wireless configuration interface of that device are impacted. Versions beyond 1.13 are not listed as vulnerable.

Risk and Exploitability

The CVSS score of 7.2 classifies this as a high severity issue. The EPSS score is not available, and it is not currently listed in CISA KEV. Exploitation requires the ability to modify the WPA‑PSK value via the device’s administrative interface, implying a local or privileged attack vector. The consequences are significant: an attacker who can gain administrative control can execute arbitrary commands as root, compromising the entire device and potentially the associated network. The lack of a publicly disclosed exploit does not diminish the risk posed by the high severity and the easy injection vector.

Generated by OpenCVE AI on September 10, 2026 at 09:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade GeoVision GV‑LPC2011/LPC2211 firmware to a patched version newer than 1.13.
  • Limit administrative access to the wireless configuration interface and ensure only trusted personnel have such privileges.
  • Implement input validation or sanitization for the WPA‑PSK field to reject shell metacharacters, and monitor configuration changes for suspicious activity.

Generated by OpenCVE AI on September 10, 2026 at 09:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to execute arbitrary commands as root when wireless configuration is applied.
Title GV-LPC2011/LPC2211 - Wireless WPA-PSK Command Injection
First Time appeared Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211
Weaknesses CWE-78
CPEs cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*
Vendors & Products Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Geovision Inc. Gv-lpc2011 Lpc2211
cve-icon MITRE

Status: PUBLISHED

Assigner: GV

Published:

Updated: 2026-09-10T15:42:01.680Z

Reserved: 2026-09-10T02:56:02.025Z

Link: CVE-2026-88275

cve-icon Vulnrichment

Updated: 2026-09-10T15:41:13.694Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T09:17:04.450

Modified: 2026-09-10T16:18:09.250

Link: CVE-2026-88275

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T09:30:10Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')