CVE-2026-88275: GV-LPC2011/LPC2211 - Wireless WPA-PSK Command Injection
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to execute arbitrary commands as root when wireless configuration is applied.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GeoVision GV-LPC2211to a version that resolves this vulnerability.Fixed in V1.13 - Compensating control
Avoid applying/using WPA-PSK values that contain shell syntax, since an administrator-controlled WPA-PSK with shell syntax can execute arbitrary commands as root when wireless configuration is applied.
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs administrator-level access to the GV-LPC2211 wireless configuration interface or another way to control the WPA-PSK value. Network reachability alone is not sufficient because the vulnerability requires high privileges.
When does the injected command run, and with what privileges?
The command is executed when the wireless configuration is applied. It runs as root, so successful exploitation can fully compromise the device's confidentiality, integrity, and availability.
How can I tell whether a device may be affected?
The affected product identified is GeoVision GV-LPC2211 version 1.13. Review devices running that version and inspect administrative access to wireless settings, particularly WPA-PSK changes containing shell-special characters or unexpected values.