Executive brief
GeoVision GV-LPC2211 is an IP camera used in surveillance systems. An authenticated administrator can inject shell commands through the WPA-PSK (WiFi password) field, and when wireless configuration is applied, these commands execute with root privileges. This allows a malicious administrator to take full control of the device and potentially compromise video feeds or use it as a foothold to attack the broader network.
Technical details
The vulnerability is a command injection flaw in the wireless configuration component of GeoVision GV-LPC2211 V1.13. When an administrator sets the WPA-PSK (WiFi pre-shared key), the input is not properly sanitized before being passed to shell execution during configuration application. An attacker with administrator credentials can embed shell metacharacters and commands (e.g., backticks, pipes, semicolons) in the WPA-PSK field to achieve arbitrary command execution as root. The vulnerability requires administrator authentication and is triggered when the wireless configuration is saved/applied. No patch status is indicated in the advisory.
Affected products
- GeoVision GV-LPC2211 V1.13
Timeline
- 2026-09-10: disclosed