Description
An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An attacker can modify a configuration value to trigger this vulnerability.
Problem types
CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')
Product status
1.10
1.12
Timeline
| 2026-02-17: | Initial Vendor Contact |
Credits
Philippe Laulheret of Cisco Talos.
Kelly Patterson of Cisco Talos.
Martin Zeiser of Cisco Talos.
References
www.geovision.com.tw/cyber_security.php
talosintelligence.com/vulnerability_reports/