← back
CVE-2024-11120

GeoVision EOL devices - OS Command Injection

CVSS 9.8 CRITICALEPSS 28.6%● KEVCWE-78
In short

GeoVision end-of-life devices allow attackers to run harmful commands on the device without logging in. This is a serious flaw that attackers are already actively exploiting to take control of these devices.

Technical detail

OS command injection vulnerability in EOL GeoVision devices permits unauthenticated remote attackers to inject and execute arbitrary system commands via unsanitized input. The attack requires network access to the device but no authentication credentials; successful exploitation grants full system-level access and has been actively weaponized in the wild.

Summary generated and translated by AI from the official description.
Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →