Description
GeoVision GV-LPC2211 V1.13 allows an authenticated ONVIF user to inject shell commands through ConsumerReference.Address and execute arbitrary commands as root.
Published: 2026-09-10
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Command Execution
Action: Patch Now
AI Analysis

Impact

GeoVision GV‑LPCLPC2011/2211 firmware version 1.13 permits an authenticated ONVIF user to inject arbitrary shell commands through the ConsumerReference.Address field, allowing execution of commands as root. The vulnerability exposes the device to full system compromise under the credentials of any authenticated user.

Affected Systems

Devices running GeoVision Inc.’s GV‑LPCLPC2011/2211 camera firmware 1.13 and 1.14 are affected. These firmware releases include the vulnerable ONVIF implementation; newer firmware builds are not specifically listed as affected in the available data.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.8, indicating high severity. EPSS data is unavailable and the issue is not in the CISA KEV catalog. Exploitation requires access to an authenticated ONVIF account and network connectivity to the camera. Once exploited, an attacker can run arbitrary commands as root, potentially compromising the entire device and any connected systems.

Generated by OpenCVE AI on September 10, 2026 at 09:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the camera firmware to a release that includes the command‑injection fix from GeoVision.
  • Restrict ONVIF access to trusted administrators and limit the camera’s exposure by placing it behind a firewall or VPN.
  • If an updated firmware is not yet available, disable the ConsumerReference.Address functionality or block the relevant ONVIF endpoints to prevent command injection.

Generated by OpenCVE AI on September 10, 2026 at 09:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description GeoVision GV-LPC2211 V1.13 allows an authenticated ONVIF user to inject shell commands through ConsumerReference.Address and execute arbitrary commands as root.
Title GV-LPCLPC2011/2211 - ONVIF Subscribe Address Command Injection
First Time appeared Geovision Inc.
Geovision Inc. gv-lpclpc2011 2211
Weaknesses CWE-78
CPEs cpe:2.3:a:geovision_inc.:gv-lpclpc2011_2211:1.13:*:*:*:*:*:*:*
cpe:2.3:a:geovision_inc.:gv-lpclpc2011_2211:1.14:*:*:*:*:*:*:*
Vendors & Products Geovision Inc.
Geovision Inc. gv-lpclpc2011 2211
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Geovision Inc. Gv-lpclpc2011 2211
cve-icon MITRE

Status: PUBLISHED

Assigner: GV

Published:

Updated: 2026-09-10T17:19:04.393Z

Reserved: 2026-09-10T02:56:02.025Z

Link: CVE-2026-88277

cve-icon Vulnrichment

Updated: 2026-09-10T17:18:57.918Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T09:17:04.673

Modified: 2026-09-10T18:18:15.407

Link: CVE-2026-88277

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T09:30:10Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')