CVE-2024-11120
GeoVision EOL devices - OS Command Injection
In short
GeoVision end-of-life devices allow attackers to run harmful commands on the device without logging in. This is a serious flaw that attackers are already actively exploiting to take control of these devices.
Technical detail
OS command injection vulnerability in EOL GeoVision devices permits unauthenticated remote attackers to inject and execute arbitrary system commands via unsanitized input. The attack requires network access to the device but no authentication credentials; successful exploitation grants full system-level access and has been actively weaponized in the wild.
Summary generated and translated by AI from the official description.
Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
GeoVision · GV-DSP_LPR_V3GeoVision · GVLX 4 V2GeoVision · GVLX 4 V3GeoVision · GV-VS11GeoVision · GV-VS12Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →