Impact
GeoVision’s GV‑LPC2211 firmware version 1.13 contains a command‑injection flaw found in the handling of WEP key1‑key4 fields. The vulnerability, identified as CWE‑78, allows an attacker who can set those keys to inject shell syntax that the device executes as the root user. This flaw can give an adversary full control of the camera and the network segment it is attached to, enabling tampering, data exfiltration, and persistence.
Affected Systems
The affected product is GeoVision’s GV‑LPC2211 camera system. Firmware releases 1.13 and 1.14 (as listed in the CPE entries from GeoVision) contain the vulnerable code. Any camera running one of these firmware versions with the web management interface enabled is susceptible.
Risk and Exploitability
The CVSS score of 7.2 denotes high severity. The EPSS score is not available, so the exact likelihood of exploitation is unknown, but the vulnerability is not listed in CISA’s KEV catalog. Attack requires that an adversary has the ability to configure the WEP keys, which implies authenticated access to the device’s administrative console or a local attack with sufficient privileges (inferred). Once this precondition is met, the injected commands run with root privileges, making the impact critical.
OpenCVE Enrichment