CVE-2026-0855 HIGH

CVE-2026-0855: Merit LILIN|IP Camera - OS Command Injection

Vendor Merit Lilin
Product P2
Weakness CWE-78
Published January 12, 2026
Last update January 16, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Certain IP Camera models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the device.

Key dates

02Disclosure timeline

January 12, 2026 CVE published
January 16, 2026 Record updated