CVE-2026-88282: GV-LPCLPC2011/2211 - Stored FTP-Username Command Injection
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled FTP username containing shell metacharacters to be executed as arbitrary root commands during a subsequent FTP-account update.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GeoVision GV-LPC2211to a version that resolves this vulnerability.Fixed in V1.13
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An authenticated administrator who can control the configured FTP username can exploit it. The attack vector is network-accessible, but it requires high privileges and no user interaction.
When does the injected command run?
The FTP username is stored first, and shell metacharacters in that value are executed during a subsequent FTP-account update. Successful exploitation results in arbitrary commands running as root.
What is the impact if exploitation succeeds?
An attacker can execute arbitrary root commands on the affected device. This can compromise confidentiality, integrity, and availability.