CVE-2026-88276
GeoVision GV-LPC2211 V1.13 allows administrator-controlled WEP key values containing shell syntax to execute arbitrary commands as root.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.2
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-78
- Published
- 2026-09-10
- Last modified
- 2026-09-10
Affected products
- GeoVision Inc. GV-LPCLPC2011/2211
- GeoVision Inc. GV-LPCLPC2011/2211
Weakness type
Related vulnerabilities
- CVE-2026-64837 — ICEcoder through 8.1 OS Command Injection via lib/properties.php
- CVE-2026-88889 — Renovate before 44.14.7 Command Injection via distributionType
- CVE-2026-88888 — Renovate before 44.14.7 Command Injection via Mix organization
- CVE-2026-88886 — Renovate before 44.14.7 Command Injection via gradle-wrapper
- CVE-2026-88885 — Renovate before 44.14.7 Command Injection via depName
- CVE-2026-13745 — Arbitrary Code Execution in Gemini CLI via Symlinked Environment Variables
- CVE-2026-88282 — GV-LPCLPC2011/2211 - Stored FTP-Username Command Injection
- CVE-2026-88277 — GV-LPCLPC2011/2211 - ONVIF Subscribe Address Command Injection