SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-88282

HIGH · CVSS 7.2 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

GeoVision GV-LPC2211 V1.13 is vulnerable to a high-severity command injection flaw that allows an attacker to execute arbitrary root commands by manipulating the FTP username with shell metacharacters during FTP-account updates. This vulnerability poses a significant risk to system integrity and could lead to unauthorized access or control over the affected devices. Organizations using this product should prioritize patching or mitigating this vulnerability to safeguard their systems against potential exploitation.

CVE
CVE-2026-88282
Severity
HIGH
CVSS
7.2
EPSS
0.30%

Original NVD Description

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled FTP username containing shell metacharacters to be executed as arbitrary root commands during a subsequent FTP-account update.