CVE-2026-42364
An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An attacker can modify a configuration value to trigger this vulnerability.
View on NVDAnalysis
This vulnerability affects the firmware of GeoVision license plate recognition cameras, allowing for arbitrary command execution. While the severity is critical, the product is specialized security hardware and is not relevant to the general-purpose software development or infrastructure stack of the community.
Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HCWE-78EPSS
Affects
geovision:gv-lpc2011_firmwaregeovision:gv-lpc2011geovision:gv-lpc2211_firmwaregeovision:gv-lpc2211Technical description
An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An attacker can modify a configuration value to trigger this vulnerability.