ZeroHour

CVE-2024-6047

KEV PoC large

Unauthenticated OS Command Injection in End-of-Life GeoVision Devices

CISA: GeoVision Devices OS Command Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
10%p95
Published
()
KEV added
AI analysis

CVE-2024-6047 is an unauthenticated OS command injection flaw (CWE-78) in certain end-of-life GeoVision surveillance devices, which fail to properly filter user input for a specific functionality. A remote attacker can trigger it by sending crafted input to the affected device over the network with no authentication required, causing arbitrary system commands to be injected and executed on the device. Successful exploitation grants attackers control of the device, which has been leveraged to recruit GeoVision units into Mirai botnets. Organizations still running the listed EOL GeoVision devices (e.g., GV-BX, GV-CB, GV-EBL, GV-EFD, GV-FD, GV-FE series devices, GV-DSP LPR units, and GV-VS14/GV-GM8186 VS14 units) are affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-05-07, Akamai has documented active Mirai-based exploitation, and EPSS puts the 30-day exploitation probability at about 10%.

What to do: Inventory internet-facing GeoVision devices, identify the listed EOL models, and apply mitigations per vendor instructions (e.g., restrict web/management access to trusted networks) or discontinue use and replace the devices if mitigations are unavailable, since the affected devices are end-of-life. US federal agencies must remediate per BOD 22-01 following the KEV listing. Given active Mirai botnet exploitation and ~10% EPSS, prioritize devices exposed to the internet and check for anomalous outbound traffic consistent with botnet activity.

Affected
GeoVision GV-DSP LPR firmwareEnd-of-life firmware; all versions, no fixed release listed in available data
GeoVision GV-BX130 firmwareEnd-of-life firmware; all versions, no fixed release listed in available data
GeoVision GV-BX1500 firmwareEnd-of-life firmware; all versions, no fixed release listed in available data
GeoVision GV-CB220 firmwareEnd-of-life firmware; all versions, no fixed release listed in available data
GeoVision GV-EBL1100 firmwareEnd-of-life firmware; all versions, no fixed release listed in available data
GeoVision GV-EFD1100 firmwareEnd-of-life firmware; all versions, no fixed release listed in available data
GeoVision GV-FD2410 firmwareEnd-of-life firmware; all versions, no fixed release listed in available data
GeoVision GV-FD3400 firmwareEnd-of-life firmware; all versions, no fixed release listed in available data
GeoVision GV-FE3401 firmwareEnd-of-life firmware; all versions, no fixed release listed in available data
GeoVision GV-FE420 firmwareEnd-of-life firmware; all versions, no fixed release listed in available data
GeoVision GV-GM8186 VS14 firmwareEnd-of-life firmware; all versions, no fixed release listed in available data
GeoVision GV-VS14 firmwareEnd-of-life firmware; all versions, no fixed release listed in available data
Estimated exposure
largeLikely tens of thousands of internet-exposed GeoVision devices (order of magnitude 10k–100k); exact count unknown — Estimate based on GeoVision's broad installed base of IP surveillance hardware and typical counts of GeoVision devices visible in public internet-exposure scans, narrowed to the EOL models CISA lists; no vendor install figures are provided…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.

CISA Known Exploited Vulnerability
Affected
GeoVision Multiple Devices
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
geovision
Products
gv-dsp lpr firmware, gv-bx130 firmware, gv-bx1500 firmware, gv-cb220 firmware, gv-ebl1100 firmware, gv-efd1100 firmware, gv-fd2410 firmware, gv-fd3400 firmware, gv-fe3401 firmware, gv-fe420 firmware, gv-gm8186 vs14 firmware, gv-vs14 firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news