ZeroHour

CVE-2024-11120

KEV PoC large

Unauthenticated OS Command Injection in GeoVision Devices

CISA: GeoVision Devices OS Command Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
28%p98
Published
()
KEV added
AI analysis

Multiple GeoVision devices contain an unauthenticated OS command injection flaw (CWE-78) that allows a remote attacker to inject and execute arbitrary system commands on the device. Because no authentication is required, any party that can reach an affected device's network services can trigger the flaw with crafted input; no public proof-of-concept is known. Successful exploitation gives the attacker remote command execution on the device, which can be used to compromise surveillance infrastructure or pivot into connected networks. Organizations running GeoVision devices are affected, and CISA notes the impacted products may be end-of-life (EoL) and/or end-of-service (EoS), meaning some may no longer receive fixes. The vulnerability was added to the CISA Known Exploited Vulnerabilities catalog on 2025-05-07, confirming exploitation in the wild; EPSS estimates a 28.4% probability of exploitation in the next 30 days (98th percentile), and ransomware use is not yet confirmed.

What to do: Inventory all GeoVision devices (including EoL/EoS models) and consult the vendor advisory for affected models and any available firmware mitigations or patches. Restrict internet exposure of GeoVision devices while remediating (firewall rules/ACLs, remove direct port forwarding), and replace or retire EoL/EoS units if the vendor offers no mitigation. Because the flaw is confirmed exploited in the wild, check devices for signs of compromise and unusual outbound traffic.

Affected
GeoVision
Estimated exposure
largeon the order of tens of thousands of internet-exposed GeoVision devices, with a larger legacy installed base — GeoVision cameras and NVRs are commonly deployed with direct internet exposure and public internet scans typically index tens of thousands of GeoVision devices, while the long-lived installed base of EoL/EoS models is likely substantially…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.

CISA Known Exploited Vulnerability
Affected
GeoVision Multiple Devices
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
geovision
Products
gv-vs12 firmware, gv-vs11 firmware, gv-dsp lpr firmware, gvlx 4 firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news