CVE-2026-88274: GV-LPC2011/LPC2211 - Wireless SSID Command Injection
Published Sep 10, 2026
·Updated
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless SSID containing shell syntax to execute arbitrary commands as root.
Affected Software
1 affected component
GeoVision GV-LPC2011/LPC2211=V1.13
Event History
Sep 10, 2026
CVE Published
via MITRE·08:20 AM
Data Sourced
via MITRE·08:20 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker must have administrator-level control sufficient to set the device's wireless SSID. Exploitation does not require user interaction and can be performed over the network.
2
What is the impact of successful exploitation?
Shell syntax in the administrator-controlled SSID can cause arbitrary commands to run as root. This can compromise confidentiality, integrity, and availability of the affected device.
3
Which versions are identified as affected?
The provided information specifically identifies GeoVision GV-LPC2211 version 1.13. It also lists the GV-LPC2011/LPC2211 product family, but does not specify affected versions for GV-LPC2011.