CVE-2026-42364
high
CVSS v3
8.8
CVSS v2
—
VIR risk
8.8
Description
An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An attacker can modify a configuration value to trigger this vulnerability.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: 0df08a0e-a200-4957-9bb0-084f562506f9 — https://www.geovision.com.tw/cyber_security.php
References
CWEs
CWE-78
Verify integrity in audit chain (admin only). AS-IS.