CVE-2026-0855
OS Command Injection in Merit LILIN IP Cameras Enables Remote Execution

Publication date: 2026-01-12

Last updated on: 2026-01-12

Assigner: TWCERT/CC

Description
Certain IP Camera models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the device.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Affected Vendors & Products
Vendor Product Version
merit_lilin ip_camera p2
merit_lilin ip_camera p3
merit_lilin ip_camera z7
merit_lilin ip_camera p6
merit_lilin ip_camera v1
merit_lilin ip_camera ipd
merit_lilin ip_camera ipr
merit_lilin ip_camera ld
merit_lilin ip_camera lr
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

CVE-2026-0855 is an OS Command Injection vulnerability found in certain Merit LILIN IP Camera models (P2, P3, Z7, P6, V1, IPD, IPR, LD, and LR series). It allows an authenticated remote attacker to inject and execute arbitrary operating system commands on the affected device, potentially compromising the device's security. [1, 2]


How can this vulnerability impact me? :

This vulnerability can have a high impact on confidentiality, integrity, and availability of the affected IP cameras. An attacker who successfully exploits it can execute arbitrary OS commands remotely, potentially leading to unauthorized access, data leakage, device manipulation, or denial of service. Some affected models are no longer supported and should be replaced, while others require firmware updates to mitigate the risk. [1, 2]


What immediate steps should I take to mitigate this vulnerability?

Immediate mitigation steps include updating the firmware of affected Merit LILIN IP Camera models according to the official advisory M00176. For unsupported models (IPD, IPR, LD, and LR series), replacement of the devices is recommended to avoid exposure to this OS Command Injection vulnerability. [1, 2]


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart
Meta Information
CVE Publication Date:
2026-01-12
CVE Last Modified Date:
2026-01-12
Report Generation Date:
2026-02-10
AI Powered Q&A Generation:
2026-01-12
EPSS Last Evaluated Date:
2026-02-09
NVD Report Link: