Executive brief
GeoVision GV-LPC2211 is an IP license plate recognition camera used in traffic monitoring and access control systems. An authenticated attacker with ONVIF user credentials can inject shell commands through the ConsumerReference.Address field and execute arbitrary code with root privileges, compromising the entire camera and potentially enabling lateral movement into the network.
Technical details
This is a command injection vulnerability in the ONVIF interface of GeoVision GV-LPC2211 V1.13. The vulnerability exists in the ConsumerReference.Address parameter, which is not properly sanitized before being passed to a system shell. An attacker who has valid ONVIF user authentication can craft a malicious ConsumerReference.Address value containing shell metacharacters to execute arbitrary commands as the root user. The attack requires network access to the camera's ONVIF service and valid authentication credentials. Exploitation allows complete compromise of the device, including data theft, persistent backdoors, and use as a pivot point for network attacks.
Affected products
- GeoVision GV-LPC2211 V1.13
Timeline
- 2026-09-10: disclosed