Impact
GeoVision GV-LPC2211 V1.13 allows an attacker who can control an administrator‑managed FTP username to inject shell metacharacters that are executed with root privileges when the account is subsequently updated. This stored command injection (CWE-78) provides the attacker with arbitrary root command execution on the device.
Affected Systems
The vulnerability affects GeoVision Inc.’s GV‑LPCLPC2011/2211 devices running firmware versions 1.13 and 1.14.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The attack requires the ability to submit a modified FTP username, which typically presumes administrative access. Based on the description, the likely attack vector is a local or remote administrator capable of modifying FTP user data. The risk is significant because the injected commands run with root privileges, enabling full system compromise once the flaw is exploited.
OpenCVE Enrichment