Executive brief
GeoVision GV-LPC2211 is a license plate recognition camera used in automated toll and parking enforcement systems. A vulnerability in version 1.13 allows an administrator to inject shell commands through WEP key configuration fields, leading to arbitrary code execution as root. An attacker with administrative access could compromise the camera and potentially the entire surveillance network it connects to.
Technical details
The vulnerability is a command injection flaw in the WEP key configuration parameter of GeoVision GV-LPC2211 v1.13. The vulnerable component fails to properly sanitize administrator-supplied WEP key values before passing them to shell execution contexts. An attacker with administrative credentials can inject shell metacharacters and syntax into the WEP key field to execute arbitrary commands with root privileges on the device. This requires authentication as an administrator but does not require user interaction beyond submitting a malicious configuration. No public patch information is currently available in the advisory.
Affected products
- GeoVision GV-LPC2211 1.13
Timeline
- 2026-09-10: disclosed