Impact
GeoVision GV‑LPCLPC2011/2211 firmware version 1.13 permits an authenticated ONVIF user to inject arbitrary shell commands through the ConsumerReference.Address field, allowing execution of commands as root. The vulnerability exposes the device to full system compromise under the credentials of any authenticated user.
Affected Systems
Devices running GeoVision Inc.’s GV‑LPCLPC2011/2211 camera firmware 1.13 and 1.14 are affected. These firmware releases include the vulnerable ONVIF implementation; newer firmware builds are not specifically listed as affected in the available data.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, indicating high severity. EPSS data is unavailable and the issue is not in the CISA KEV catalog. Exploitation requires access to an authenticated ONVIF account and network connectivity to the camera. Once exploited, an attacker can run arbitrary commands as root, potentially compromising the entire device and any connected systems.
OpenCVE Enrichment