CVE-2026-42364
EUVD-2026-2685504.05.2026, 01:16
An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An attacker can modify a configuration value to trigger this vulnerability.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| geovision | gv-lpc2011_firmware | 1.10 |
| geovision | gv-lpc2211_firmware | 1.10 |
𝑥
= Vulnerable software versions