CVE-2026-88276: GV-LPCLPC2011/2211 - Wireless WEP Key1-Key4 Command Injection
Published Sep 10, 2026
·Updated
GeoVision GV-LPC2211 V1.13 allows administrator-controlled WEP key values containing shell syntax to execute arbitrary commands as root.
Affected Software
1 affected component
GeoVision GV-LPC2211=V1.13
Event History
Sep 10, 2026
CVE Published
via MITRE·08:21 AM
Data Sourced
via MITRE·08:21 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attacker must have administrator-level control over the device configuration, because exploitation requires setting WEP Key1 through Key4 to values containing shell syntax.
2
What is the impact if exploitation succeeds?
An attacker can execute arbitrary commands as root on the affected GeoVision GV-LPC2211 V1.13 device. This can compromise confidentiality, integrity, and availability.
3
Which configuration fields should be reviewed for signs of exploitation?
Review the Wireless WEP Key1, Key2, Key3, and Key4 values for shell syntax or unexpected command-like content. These administrator-controlled fields are the identified injection points.