CVE-2024-6047
KEV PoC largeUnauthenticated OS Command Injection in End-of-Life GeoVision Devices
CISA: GeoVision Devices OS Command Injection Vulnerability
CVE-2024-6047 is an unauthenticated OS command injection flaw (CWE-78) in certain end-of-life GeoVision surveillance devices, which fail to properly filter user input for a specific functionality. A remote attacker can trigger it by sending crafted input to the affected device over the network with no authentication required, causing arbitrary system commands to be injected and executed on the device. Successful exploitation grants attackers control of the device, which has been leveraged to recruit GeoVision units into Mirai botnets. Organizations still running the listed EOL GeoVision devices (e.g., GV-BX, GV-CB, GV-EBL, GV-EFD, GV-FD, GV-FE series devices, GV-DSP LPR units, and GV-VS14/GV-GM8186 VS14 units) are affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-05-07, Akamai has documented active Mirai-based exploitation, and EPSS puts the 30-day exploitation probability at about 10%.
What to do: Inventory internet-facing GeoVision devices, identify the listed EOL models, and apply mitigations per vendor instructions (e.g., restrict web/management access to trusted networks) or discontinue use and replace the devices if mitigations are unavailable, since the affected devices are end-of-life. US federal agencies must remediate per BOD 22-01 following the KEV listing. Given active Mirai botnet exploitation and ~10% EPSS, prioritize devices exposed to the internet and check for anomalous outbound traffic consistent with botnet activity.
| GeoVision GV-DSP LPR firmware | End-of-life firmware; all versions, no fixed release listed in available data |
| GeoVision GV-BX130 firmware | End-of-life firmware; all versions, no fixed release listed in available data |
| GeoVision GV-BX1500 firmware | End-of-life firmware; all versions, no fixed release listed in available data |
| GeoVision GV-CB220 firmware | End-of-life firmware; all versions, no fixed release listed in available data |
| GeoVision GV-EBL1100 firmware | End-of-life firmware; all versions, no fixed release listed in available data |
| GeoVision GV-EFD1100 firmware | End-of-life firmware; all versions, no fixed release listed in available data |
| GeoVision GV-FD2410 firmware | End-of-life firmware; all versions, no fixed release listed in available data |
| GeoVision GV-FD3400 firmware | End-of-life firmware; all versions, no fixed release listed in available data |
| GeoVision GV-FE3401 firmware | End-of-life firmware; all versions, no fixed release listed in available data |
| GeoVision GV-FE420 firmware | End-of-life firmware; all versions, no fixed release listed in available data |
| GeoVision GV-GM8186 VS14 firmware | End-of-life firmware; all versions, no fixed release listed in available data |
| GeoVision GV-VS14 firmware | End-of-life firmware; all versions, no fixed release listed in available data |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.
- Affected
- GeoVision Multiple Devices
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- geovision
- Products
- gv-dsp lpr firmware, gv-bx130 firmware, gv-bx1500 firmware, gv-cb220 firmware, gv-ebl1100 firmware, gv-efd1100 firmware, gv-fd2410 firmware, gv-fd3400 firmware, gv-fe3401 firmware, gv-fe420 firmware, gv-gm8186 vs14 firmware, gv-vs14 firmware
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H