No advisories yet.
Solution
GeoVision GV-LPC2011/LPC2211 V1.12-260330 has patched the reported vulnerability. The user may visit GeoVision website or contact GeoVision Support team for firmware update.
Workaround
No workaround given by the vendor.
Mon, 04 May 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An attacker can modify a configuration value to trigger this vulnerability. | |
| Title | GeoVision LPC2011/LPC2211 Web Interface / DdnsSetting.cgi OS command injection vulnerability | |
| First Time appeared |
Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211 |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.10:*:linux:*:*:*:*:* cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.12:*:linux:*:*:*:*:* |
|
| Vendors & Products |
Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GV
Published:
Updated: 2026-05-04T00:41:33.908Z
Reserved: 2026-04-26T23:39:08.350Z
Link: CVE-2026-42364
No data.
Status : Received
Published: 2026-05-04T01:16:03.470
Modified: 2026-05-04T01:16:03.470
Link: CVE-2026-42364
No data.
OpenCVE Enrichment
Updated: 2026-05-04T02:30:34Z