CVE-2026-0855
OS Command Injection in Merit LILIN IP Cameras Enables Remote Execution

Publication date: 2026-01-12

Last updated on: 2026-01-12

Assigner: [email protected]

Description
Certain IP Camera models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the device.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Affected Vendors & Products
Vendor Product Version
merit_lilin ip_camera p6
merit_lilin ip_camera z7
merit_lilin ip_camera p2
merit_lilin ip_camera p3
merit_lilin ip_camera v1
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?


How can this vulnerability impact me? :


What immediate steps should I take to mitigate this vulnerability?


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart
Meta Information
CVE Publication Date:
2026-01-12
CVE Last Modified Date:
2026-01-12
Report Generation Date:
2026-01-15
AI Powered Q&A Generation:
2026-01-12
EPSS Last Evaluated Date:
2026-01-14
NVD Report Link: