7.2
CVE-2026-88282
- EPSS 0.3%
- Veröffentlicht 10.09.2026 08:23:11
- Zuletzt bearbeitet 10.09.2026 16:18:09
- Erkennungen
GV-LPCLPC2011/2211 - Stored FTP-Username Command Injection
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled FTP username containing shell metacharacters to be executed as arbitrary root commands during a subsequent FTP-account update.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerGeoVision Inc.
≫
Produkt
GV-LPCLPC2011/2211
Default Statusunaffected
Version
1.13
Status
affected
Version
1.14
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.225 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 0df08a0e-a200-4957-9bb0-084f562506f9 | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
https://www.geovision.com.tw/cyber_security.php