CVE-2026-42364: GeoVision LPC2011/LPC2211 Web Interface / DdnsSetting.cgi OS command injection vulnerability
An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An attacker can modify a configuration value to trigger this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GeoVision GV-LPC2011/LPC2211to a version that resolves this vulnerability.Fixed in V1.12-260330
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42364?
CVE-2026-42364 is classified as a high severity vulnerability due to its potential for arbitrary command execution.
How do I fix CVE-2026-42364?
To fix CVE-2026-42364, update the GeoVision LPC2011 or LPC2211 to the latest version that addresses the issue.
What systems are affected by CVE-2026-42364?
CVE-2026-42364 affects GeoVision LPC2011 and LPC2211 devices running version 1.10.
What type of attack is possible with CVE-2026-42364?
CVE-2026-42364 allows attackers to execute arbitrary commands on the system through crafted DDNS configurations.
Is CVE-2026-42364 actively exploited in the wild?
Currently, there is no public information indicating that CVE-2026-42364 is actively exploited in the wild.