CameraRisk

CVE-2024-6047

GeoVision · exploited in the wild

Published
17 June 2024
Last modified
17 June 2026
CVSS
9.8 v3.1
Severity
critical
EPSS
10.1% (95th pct)
CISA KEV
Added 7 May 2025 KEV
NVD status
Analyzed
Weaknesses
CWE-78

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.

Exploitation

Added to the CISA Known Exploited Vulnerabilities catalogue on 7 May 2025, with a remediation due date of 28 May 2025 for US federal civilian agencies. CISA records no known ransomware campaign use.

Required action as published by CISA: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Affected products

ProductVendorTypeVersions named
Gv-bx130 GeoVision unknown
Gv-bx1500 GeoVision unknown
Gv-cb220 GeoVision unknown
Gv-dsp Lpr GeoVision unknown 2.0, 3.0
Gv-ebl1100 GeoVision unknown
Gv-efd1100 GeoVision unknown
Gv-fd2410 GeoVision unknown
Gv-fd3400 GeoVision unknown
Gv-fe3401 GeoVision unknown
Gv-fe420 GeoVision unknown
Gv-gm8186 Vs14 GeoVision unknown
Gv-vs03 GeoVision unknown
Gv-vs04a GeoVision unknown
Gv-vs04h GeoVision unknown
Gv-vs14 GeoVision unknown
Gv-vs21600 GeoVision unknown
Gv-vs2410 GeoVision unknown
Gv-vs2800 GeoVision unknown
Gv-vs2820 GeoVision unknown
GVLX 4 GeoVision unknown 2.0, 3.0

References

CVE-2024-6047 at NVD

Record assembled from NVD, CISA KEV 2026.09.04 and FIRST EPSS 2026-09-04. Affected products are those NVD's CPE configuration names that fall inside this site's scope; a CVE may affect products outside it.