CameraRisk

CVE-2024-11120

GeoVision · exploited in the wild

Published
15 November 2024
Last modified
17 June 2026
CVSS
9.8 v3.1
Severity
critical
EPSS
28.4% (98th pct)
CISA KEV
Added 7 May 2025 KEV
NVD status
Analyzed
Weaknesses
CWE-78

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.

Exploitation

Added to the CISA Known Exploited Vulnerabilities catalogue on 7 May 2025, with a remediation due date of 28 May 2025 for US federal civilian agencies. CISA records no known ransomware campaign use.

Required action as published by CISA: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Affected products

ProductVendorTypeVersions named
Gv-dsp Lpr GeoVision unknown 2.0, 3.0
Gv-vs11 GeoVision unknown
Gv-vs12 GeoVision unknown
GVLX 4 GeoVision unknown 2.0, 3.0

References

CVE-2024-11120 at NVD

Record assembled from NVD, CISA KEV 2026.09.04 and FIRST EPSS 2026-09-04. Affected products are those NVD's CPE configuration names that fall inside this site's scope; a CVE may affect products outside it.