CVE-2026-42364Disclosure(geovision / gv-lpc2011)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch geovision gv-lpc2011 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An attacker can modify a configuration value to trigger this vulnerability.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gv-lpc2011
  • gv-lpc2011_firmware
  • gv-lpc2211
  • gv-lpc2211_firmware

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 9 signals
  • Disclosure: 6 classified signals
  • General: 3 classified signals
  • Peaked 1d ago at 5 mentions (2026-06-02); latest day: 1
  • 10 total mentions across 5 days

Affected systems

Vendors
Products
gv-lpc2011gv-lpc2011_firmwaregv-lpc2211gv-lpc2211_firmware

2 versions affected across 4 products

Deep dive

Activity timeline10 mentions / 5d
01345Mentions · 2026-05-04: 1Mentions · 2026-05-13: 2Mentions · 2026-05-15: 1Mentions · 2026-06-02: 5Mentions · 2026-06-17: 1Patch / Workaround · 2026-05-15: 1Patch / Workaround · 2026-06-02: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-15: 1Technical Details · 2026-06-02: 5Technical Details · 2026-06-17: 105-0405-1305-1506-0206-17
Signal classification3 categories
Disclosure
660.0%
General
330.0%
Patch
110.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-041
General1
2026-05-132
General2
2026-05-151
Patch1
2026-06-025
Disclosure5
2026-06-171
Disclosure1
Full discourse10 posts
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-42364 CVSS: 9.9 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces CVE-2026-42364 with a critical severity rating and detailed CVSS metrics, but offers no evidence of exploitation, PoC, or mitigation.

    2000040
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Impact vs Product vs CVSS vs Vector: CVE-2026-42369: RCE as SYSTEM (no ASLR) (vs Product GV-VMS V20 | CVSS **10.0** | Vector Remote, Unauth) CVE-2026-42370: RCE via login stack overflow (vs Product GV-VMS V20 20.0.2 | CVSS 9.0 | Vector Remote, Unauth) CVE-2026-42364: OS…

    Post summary

    The snippet lists three CVEs (CVE-2026-42369, CVE-2026-42370, CVE-2026-42364) with high severity RCE vulnerabilities, detailing product versions and CVSS scores, but contains no PoC, exploit code, or mitigation references.

    1000041
    289 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    TL;DR GeoVision GV-VMS V20 has a CVSS 10.0 unauthenticated stack overflow RCE in its WebCam Server component (CVE-2026-42369), disclosed today. A companion command injection flaw (CVE-2026-42364) hits network-connected LPC cameras at CVSS 9.9. Both allow remote code…

    Post summary

    The post announces the disclosure of two high‑impact vulnerabilities in GeoVision products, specifying RCE via stack overflow and command injection, but provides no evidence of exploitation or remediation yet.

    1000043
    238 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Simultaneously, a companion critical flaw (CVE-2026-42364) was disclosed in GeoVision LPC2011/LPC2211 network cameras—a CVSS 9.9 OS command injection in the DDNS configuration handler that allows unauthenticated attackers to inject arbitrary shell commands.

    Post summary

    The passage announces a newly disclosed critical flaw (CVE-2026-42364) in GeoVision LPC2011/LPC2211 network cameras, detailing a CVSS 9.9 OS command injection that permits unauthenticated shell injection via the DDNS configuration handler.

    1000040
    238 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    A critical OS command injection vulnerability (CVE-2026-42364, CVSS 9.9) in GeoVision LPC2011/2211 surveillance cameras (firmware 1.10) allows unauthenticated remote attackers to execute arbitrary commands by manipulating DDNS configuration values. No patch available yet.…

    Post summary

    A critical OS command injection vulnerability (CVE-2026-42364) affecting GeoVision LPC2011/2211 cameras allows unauthenticated remote command execution via DDNS configuration values, with CVSS 9.9; no patch is available yet.

    1000031
    238 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Surveillance Perimeter Just Cracked: GeoVision LPC2011/2211 Unauthenticated RCE via DDNS Injection (CVE-2026-42364). A critical OS command injection vulnerability CVE-2026-42364, CVSS 9.9 in GeoVision LPC2011/2211 surveillance cameras firmware 1.10 allows…

    Post summary

    A critical OS command injection vulnerability (CVE‑2026‑42364) with a CVSS score of 9.9 was disclosed for GeoVision LPC2011/2211 surveillance cameras, allowing unauthenticated remote code execution via DDNS injection.

    1000041
    238 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Sources The HackerWire: GeoVision LPC2011/LPC2211 Critical OS Command Injection (CVE-2026-42364) NVD: CVE-2026-42364 The Surveillance Perimeter Just Cracked: GeoVision LPC2011/2211 Unauthenticated RCE via DDNS Injection

    Post summary

    The text announces CVE‑2026‑42364 for GeoVision LPC2011/2211 as a critical OS command injection, providing technical details but no evidence of PoC, active exploitation, or patch.

    1000026
    238 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    A critical OS command injection vulnerability (CVE-2026-42364) affects GeoVision LPC2011/LPC2211 devices. SMBs and healthcare orgs using these should review device configs and patch immediately to prevent unauthorized control. #cybersecurity

    Post summary

    The post identifies a critical OS command injection vulnerability in GeoVision devices and urges immediate patching to prevent unauthorized control.

    0000046
    80 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-42364-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    Only a URL and hashtags are provided, lacking any substantive detail about the CVE. The information is insufficient for a more specific classification.

    0000025
    210 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-42364 OS Command Injection in GeoVision LPC2011/LPC2211 1.10 DdnsSettin... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42364 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet references CVE‑2026‑42364 as an OS command‑injection vulnerability in GeoVision devices but provides no proof‑of‑concept, exploit, active use, or patch information, merely linking to a vulnerability details page.

    0000051
    4.0K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
HWgeovisiongv-lpc2011---
OSgeovisiongv-lpc2011_firmware1.10--
HWgeovisiongv-lpc2211---
OSgeovisiongv-lpc2211_firmware1.10--

Explore more