CVE-2026-42364: GeoVision Gv-LPC2011 Firmware

High severity, CVSS 8.8. EPSS: 3.3% chance of exploitation in the next 30 days.

An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An attacker can modify a configuration value to trigger this vulnerability.

Affected products

  • GeoVision Gv-LPC2011 Firmware: version 1.10 only
  • GeoVision Gv-LPC2211 Firmware: version 1.10 only

Published 2026-05-04. Last modified 2026-06-17.