HarborGuard / CVE
Back to search
CRITICALCVE-2026-42364Published Modified CNA GV

CVE-2026-42364: GeoVision LPC2011/LPC2211 Web Interface / DdnsSetting.cgi OS command injection vulnerability

An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An attacker can modify a configuration value to trigger this vulnerability.

Metrics

CVSS v3.1
9.9
Severity
CRITICAL
Fixed in
1.12
Affected Products
1

Fix available

1.12
Affected packages
  • GeoVision Inc. / GV-LPC2011/LPC2211
    1.10
    Fixed in 1.12
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H