CVE-2026-88277

8.8

GeoVision · GV-LPCLPC2011/2211

GeoVision GV-LPC2211 version 1.13 is vulnerable to OS command injection via the ONVIF ConsumerReference.Address parameter, allowing authenticated users to execute arbitrary commands as root.

Executive summary

A critical command injection vulnerability in GeoVision GV-LPC2211 devices allows authenticated attackers to gain full root-level control over the system.

Vulnerability

This is an OS command injection flaw (CWE-78) triggered through the ConsumerReference.Address field in the ONVIF interface. The vulnerability requires the attacker to have authenticated access to the device, after which they can execute arbitrary system commands with root privileges.

Business impact

Successful exploitation of this vulnerability grants an attacker complete control over the affected device, potentially leading to unauthorized surveillance, network pivot attacks, or total loss of system integrity. With a CVSS score of 8.8, this represents a high-severity risk that could result in significant operational disruption and the compromise of sensitive video security infrastructure.

Remediation

Immediate Action: Update the GeoVision GV-LPC2211 firmware to version 1.14 or later to resolve the underlying command injection flaw.

Proactive Monitoring: Review access logs for the ONVIF service and monitor for suspicious shell commands or unauthorized modifications to system configuration files.

Compensating Controls: Restrict network access to the ONVIF interface to authorized management subnets only and enforce strict authentication policies to minimize the risk of malicious users gaining the required initial access.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability, combined with the potential for full system compromise via root-level command execution, necessitates immediate action. Administrators must prioritize updating all affected GeoVision units to version 1.14 or newer to eliminate the command injection vector. Ensure that all security patches are applied in accordance with the vendor's updated guidance.

More GeoVision CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo o, per the CVE Program record.