Executive brief
The GeoVision GV-LPC2211 is a network-attached device used for license plate recognition and video surveillance. A vulnerability in version 1.13 allows an administrator to inject arbitrary commands through the PPPoE username field, leading to execution of commands with root privileges. An attacker with administrative access could compromise the entire system and gain unauthorized control over surveillance infrastructure.
Technical details
This vulnerability is a command injection flaw in the PPPoE configuration module of GeoVision GV-LPC2211 V1.13. The vulnerability arises because the PPPoE username input is improperly sanitized before being incorporated into a shell configuration assignment and sourced for execution. An authenticated administrator can inject shell metacharacters (such as backticks or command substitution syntax) into the PPPoE username field to break out of the intended variable assignment context and execute arbitrary commands as root. No network-level authentication bypass is required—the attacker must have administrative access to the device. A successful exploit grants complete system compromise with root-level command execution.
Affected products
- GeoVision GV-LPC2211 V1.13
Timeline
- 2026-09-10: disclosed