Junglewise Threat Intelligence

CVE-2026-88276: GeoVision GV-LPC2211 command injection in WEP key configuration

CVE-2026-88276 · Severity: high · CVSS 7.2 · Published 2026-09-10

Technologies: Geovision Gv-Lpc2211. Vendors: Geovision.

Executive brief

GeoVision GV-LPC2211 is a license plate recognition camera used in automated toll and parking enforcement systems. A vulnerability in version 1.13 allows an administrator to inject shell commands through WEP key configuration fields, leading to arbitrary code execution as root. An attacker with administrative access could compromise the camera and potentially the entire surveillance network it connects to.

Technical details

The vulnerability is a command injection flaw in the WEP key configuration parameter of GeoVision GV-LPC2211 v1.13. The vulnerable component fails to properly sanitize administrator-supplied WEP key values before passing them to shell execution contexts. An attacker with administrative credentials can inject shell metacharacters and syntax into the WEP key field to execute arbitrary commands with root privileges on the device. This requires authentication as an administrator but does not require user interaction beyond submitting a malicious configuration. No public patch information is currently available in the advisory.

Affected products

  • GeoVision GV-LPC2211 1.13

Timeline

  • 2026-09-10: disclosed

References

Related threats