Junglewise Threat Intelligence

CVE-2026-88282: GeoVision GV-LPC2211 command injection via FTP username

CVE-2026-88282 · Severity: high · CVSS 7.2 · Published 2026-09-10

Technologies: Geovision Gv-Lpc2211. Vendors: Geovision.

Executive brief

The GeoVision GV-LPC2211 is a network-based license plate recognition camera used in traffic and access control systems. A vulnerability allows an administrator to inject shell commands through the FTP username field, which are then executed with root privileges when FTP account settings are updated. This could allow an attacker with admin access to gain complete control of the device and potentially compromise surveillance infrastructure.

Technical details

The vulnerability is a command injection flaw in the FTP account management component of GeoVision GV-LPC2211 V1.13. The affected code fails to properly sanitize the FTP username field, allowing shell metacharacters to be passed through to a system command executed with root privileges during FTP account configuration updates. An administrator must create or modify the FTP account with injected shell metacharacters (e.g. backticks, pipes, semicolons) in the username field; the payload executes when the FTP settings are saved. This requires administrative access to the device interface. An attacker with admin credentials can achieve arbitrary code execution as root, potentially leading to full device compromise. Patches or updates should be available from GeoVision for affected versions.

Affected products

  • GeoVision GV-LPC2211 V1.13

Timeline

  • 2026-09-10: disclosed

References

Related threats