CVE-2026-88277: GV-LPCLPC2011/2211 - ONVIF Subscribe Address Command Injection
Published Sep 10, 2026
·Updated
GeoVision GV-LPC2211 V1.13 allows an authenticated ONVIF user to inject shell commands through ConsumerReference.Address and execute arbitrary commands as root.
Affected Software
1 affected component
GeoVision GV-LPC2211=V1.13
Event History
Sep 10, 2026
CVE Published
via MITRE·08:21 AM
Data Sourced
via MITRE·08:21 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must be authenticated as an ONVIF user. No user interaction is required, and the vulnerable interface is reachable over the network.
2
What is the impact if exploitation succeeds?
An authenticated attacker can inject shell commands through the ConsumerReference.Address field and execute arbitrary commands as root. This can result in complete compromise of confidentiality, integrity, and availability on the device.
3
Which product version is identified as affected?
The reported affected product is GeoVision GV-LPC2211 version 1.13.