Junglewise Threat Intelligence

CVE-2026-88274: GeoVision GV-LPC2211 command injection in wireless SSID configuration

CVE-2026-88274 · Severity: high · CVSS 7.2 · Published 2026-09-10

Technologies: Geovision Gv-Lpc2211. Vendors: Geovision.

Executive brief

The GeoVision GV-LPC2211 is a license plate recognition camera used for traffic and parking enforcement. A vulnerability allows authenticated administrators to execute arbitrary commands with root privileges by injecting shell metacharacters into the wireless network name (SSID) configuration field, potentially compromising the device and any connected network.

Technical details

This is a command injection vulnerability in the GeoVision GV-LPC2211 V1.13 where the wireless SSID configuration parameter is not properly sanitized before being passed to a shell command. An authenticated administrator can craft a malicious SSID containing shell syntax (e.g., backticks, semicolons, or pipe operators) to execute arbitrary code as root. The attack requires administrator credentials and access to the device's configuration interface but does not require user interaction beyond submitting the malicious configuration. Successful exploitation results in complete device compromise with root-level code execution.

Affected products

  • GeoVision GV-LPC2211 V1.13

Timeline

  • 2026-09-10: disclosed

References

Related threats