Junglewise Threat Intelligence

CVE-2026-42364: GeoVision LPC2011/LPC2211 OS command injection in DdnsSetting.cgi

CVE-2026-42364 · Severity: critical · CVSS 9.9 · Published 2026-05-04

Technologies: Geovision Gv-Lpc2011 Firmware, Geovision Gv-Lpc2211 Firmware, Geovision Gv-Lpc2211, Geovision LPC2011 Firmware, Geovision LPC2211 Firmware, Geovision Gv-Lpc2011. Vendors: Geovision.

Executive brief

GeoVision LPC2011 and LPC2211 are specialized license plate recognition cameras used for security and traffic monitoring. A vulnerability in the device's Dynamic DNS (DDNS) settings allows an attacker with basic user credentials to execute unauthorized commands on the system. This could lead to a complete takeover of the camera, allowing the attacker to disrupt surveillance operations, access video feeds, or use the device as a foothold to attack other parts of the corporate network.

Technical details

An OS command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 firmware version 1.10. The vulnerability stems from a lack of sanitization in fields such as 'szHostname', 'username', and 'password' when processing DDNS configuration updates. An attacker can inject line breaks into these fields to insert arbitrary configuration parameters into the 'ddns.conf' file used by the 'ez-ipupdate' service. Specifically, by injecting an 'execute' parameter, an attacker can trigger the execution of shell commands with root privileges upon a successful DDNS update. While the attack requires authentication (typically admin or a user with configuration rights), it can lead to full system compromise. A patch was released by the vendor in April 2026.

Affected products

  • GeoVision LPC2011 Firmware 1.10
  • GeoVision LPC2211 Firmware 1.10

Timeline

  • 2026-02-17: other: Initial vendor contact
  • 2026-02-24: disclosed: Vendor disclosure
  • 2026-04-14: patched: Vendor patch release
  • 2026-05-04: advisory: NVD publication date
  • 2026-06-15: other: Public release by Cisco Talos

References

Related threats