← Vulnerability feed

Vulnerability record · CVE-2024-11120 · published 15 November 2024

CVE-2024-11120: GeoVision EOL Devices OS Command Injection

Geovision · Gv Vs12 Firmware

Certain end-of-life GeoVision devices contain an OS command injection flaw (CWE-78) that allows unauthenticated remote attackers to execute arbitrary system commands. The vulnerability affects multiple GeoVision firmware products and has been actively exploited in the wild, making it a serious risk for any remaining deployments.

9.8 CVSS 3.1 Critical CISA KEV since 7 May 2025 EPSS 28% · top 1.9% CWE-78 · OS command injection
9.8CVSS 3.1 base score
28%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
4Affected product versions listed by NVD
4References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, active exploitation confirmed by CISA KEV and Akamai, unauthenticated remote code execution, and high EPSS score make this an urgent risk.

What it is

Certain end-of-life GeoVision devices contain an OS command injection flaw (CWE-78) that allows unauthenticated remote attackers to execute arbitrary system commands. The vulnerability affects multiple GeoVision firmware products and has been actively exploited in the wild, making it a serious risk for any remaining deployments.

Impact

An attacker can execute arbitrary system commands on the device, leading to full compromise of confidentiality, integrity, and availability. This can enable botnet recruitment, data theft, or use of the device as a pivot point into the network.

Attack surface

The flaw is reachable over the network with no authentication or user interaction required, as indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:N). Any internet-exposed or network-accessible GeoVision device running the affected firmware is a potential target.

Exploitation

Exploitation has been confirmed: the CVE is listed in CISA KEV (added 2025-05-07) and an Akamai report documents active exploitation by Mirai botnet. EPSS probability is 0.28386 (98th percentile), indicating high likelihood of exploitation.

What to do

  • Apply vendor-provided mitigations or firmware updates if available; if the device is end-of-life and no patch exists, discontinue use or isolate it from untrusted networks.
  • Remove or block internet exposure of affected GeoVision devices; place them behind a firewall and restrict access to trusted management networks only.
  • Follow CISA BOD 22-01 guidance for cloud services and apply the required actions from the KEV catalog by the due date (2025-05-28).
  • Monitor for signs of compromise and consider replacing EOL devices with supported alternatives.

Detection

  • Monitor network traffic for command injection attempts targeting GeoVision device endpoints, looking for unusual HTTP requests containing shell metacharacters.
  • Inspect device logs for unexpected command execution, new processes, or outbound connections to known botnet C2 infrastructure.
  • Use network segmentation and IDS/IPS signatures to detect exploitation attempts against GeoVision devices.
  • Audit network for any internet-facing GeoVision devices and verify they are not running vulnerable firmware versions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-11120 to the Known Exploited Vulnerabilities catalog on 7 May 2025 as "GeoVision Devices OS Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 28 May 2025.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-11120 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-6047GeoVision EOL devices OS command injection via unfiltered inputCertain end-of-life GeoVision devices fail to filter user input in a specific function, allowing OS command injection. Unauthenticated remote attacke…KEVEPSS 10%analysed8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2026-87491Google Chrome V8 out-of-bounds write enables sandbox code executionChrome before 153.0.8010.36 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger the memory corruption, and b…KEVEPSS 3.1%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed7.8CVE-2026-83549SonicWall SMA1000 AMC OS Command InjectionThe SMA1000 Appliance Management Console contains an OS command injection flaw (CWE-78) that lets an authenticated administrator execute arbitrary op…KEVEPSS 11%analysed10.0CVE-2026-49869Kestra OSS auth bypass via path suffix match enables RCEKestra OSS AuthenticationFilter whitelists the public config endpoint using request.getPath().endsWith("/configs"), a suffix match instead of an exac…KEVEPSS 2.1%analysed7.8CVE-2026-53362Linux kernel IPv6 UDP paged allocation out-of-bounds write__ip6_append_data() in the Linux kernel mis-accounts fraggap on the paged-allocation path, leaving the linear skb area undersized while pagedlen is o…KEVEPSS 0.71%analysed7.8CVE-2022-0995Linux kernel watch_queue out-of-bounds writeThe Linux kernel's watch_queue event notification subsystem contains an out-of-bounds write (CWE-787) that can overwrite kernel state. A local user c…KEVEPSS 8.8%analysed

Source: NIST National Vulnerability Database (record CVE-2024-11120), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.