CVE-2026-0855
OS Command Injection in Merit LILIN IP Cameras Enables Remote Execution
Publication date: 2026-01-12
Last updated on: 2026-01-12
Assigner: TWCERT/CC
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Affected Vendors & Products
| Vendor | Product | Version |
|---|---|---|
| merit_lilin | ip_camera | p2 |
| merit_lilin | ip_camera | p3 |
| merit_lilin | ip_camera | z7 |
| merit_lilin | ip_camera | p6 |
| merit_lilin | ip_camera | v1 |
| merit_lilin | ip_camera | ipd |
| merit_lilin | ip_camera | ipr |
| merit_lilin | ip_camera | ld |
| merit_lilin | ip_camera | lr |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-78 | The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
CVE-2026-0855 is an OS Command Injection vulnerability found in certain Merit LILIN IP Camera models (P2, P3, Z7, P6, V1, IPD, IPR, LD, and LR series). It allows an authenticated remote attacker to inject and execute arbitrary operating system commands on the affected device, potentially compromising the device's security. [1, 2]
How can this vulnerability impact me? :
This vulnerability can have a high impact on confidentiality, integrity, and availability of the affected IP cameras. An attacker who successfully exploits it can execute arbitrary OS commands remotely, potentially leading to unauthorized access, data leakage, device manipulation, or denial of service. Some affected models are no longer supported and should be replaced, while others require firmware updates to mitigate the risk. [1, 2]
What immediate steps should I take to mitigate this vulnerability?
Immediate mitigation steps include updating the firmware of affected Merit LILIN IP Camera models according to the official advisory M00176. For unsupported models (IPD, IPR, LD, and LR series), replacement of the devices is recommended to avoid exposure to this OS Command Injection vulnerability. [1, 2]