CVE-2026-88272: GV-LPC2011/LPC2211 - Stored Administrator-Username Command Injection
Published Sep 10, 2026
·Updated
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled username containing shell metacharacters to be executed as arbitrary root commands when the stored username is later deleted.
Affected Software
1 affected component
GeoVision GV-LPC2211=1.13
Event History
Sep 10, 2026
CVE Published
via MITRE·08:19 AM
Data Sourced
via MITRE·08:19 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs administrator-level control of a username. Exploitation occurs when that stored username is later deleted, causing shell metacharacters in the username to be executed.
2
What level of access can exploitation provide?
The injected commands can run with root privileges. This can affect confidentiality, integrity, and availability of the device.
3
How can administrators identify potentially affected accounts?
Review administrator-controlled usernames for shell metacharacters, particularly accounts that may later be deleted. The affected product and version identified are GeoVision GV-LPC2211 V1.13.