LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-11120: GeoVision Devices OS Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 7, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 28, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-11120 to its Known Exploited Vulnerabilities catalog on May 7, 2025, with a federal patch deadline of May 28, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacted products could be…

CVE-2024-11120 is an OS command injection vulnerability affecting multiple GeoVision devices. A remote, unauthenticated attacker can inject and execute arbitrary system commands on the device. This matters because successful abuse can give full control of the appliance, which often sits on networks with cameras, access control, or other security infrastructure. Some of the impacted products may already be end-of-life or end-of-service, so vendor support and patches may be limited or unavailable.

Defenders should treat any internet-facing or poorly segmented GeoVision device as high priority until they confirm it is not vulnerable or has been removed from service. Confirm all product-specific details against the vendor advisory and CISA guidance.

How it works

The flaw is classified as CWE-78: Improper Neutralization of Special Elements used in an OS Command. In this class of weakness, user-supplied input reaches a system shell or command interpreter without proper sanitization or parameterization. An attacker who can reach the vulnerable interface supplies crafted input that breaks out of the intended command and appends additional OS commands of their choosing.

Because the attack requires no authentication and can be performed remotely, any network path that reaches the device’s management or service interfaces is sufficient. Once the injected command runs with the privileges of the vulnerable process, the attacker can typically read or write files, create accounts, install persistence, or pivot further into the network. Exact injection points and request formats are not detailed here; those must be confirmed in the vendor advisory.

Am I affected? How to find it in your systems

GeoVision devices are commonly deployed as IP cameras, video recorders, access-control controllers, and related surveillance or security appliances. They may appear on corporate, industrial, or remote-site networks, sometimes with management ports exposed to the internet or to large internal segments.

Because public technical detail is limited, treat any unpatched or unsupported GeoVision device that accepts remote connections as potentially vulnerable until proven otherwise.

How to remediate

The primary remediation path is to apply the mitigations or updates published by the vendor. Follow the exact instructions in the GeoVision advisory for each model. CISA’s required action is to apply those vendor mitigations, follow applicable BOD 22-01 guidance for any cloud-connected services, or discontinue use of the product if mitigations are unavailable.

Document the remediation status of every identified unit so that residual risk can be tracked.

If you can't patch immediately

When an immediate update or replacement is not possible, reduce the attack surface with compensating controls while a permanent fix is arranged.

These steps do not eliminate the vulnerability; they only lower the likelihood of successful remote exploitation until the device is patched or retired.

If your data may have been exposed

Actively exploited vulnerabilities of this class frequently lead to full device compromise and subsequent lateral movement or data theft. Although ransomware use has not been documented for this specific CVE, any successful command injection can still result in credential harvesting, video-stream interception, or network foothold. If you suspect a device was reachable and unpatched during the period of exposure, treat it as potentially compromised: isolate it, collect forensic images if feasible, rotate any credentials that may have been stored or transmitted through it, and review adjacent systems for signs of further intrusion. You can also run a free exposure scan of your email addresses against known breach data sets to check whether related accounts have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedGeoVision · Multiple Devices
WeaknessCWE-78
Added to CISA KEVMay 7, 2025
Federal patch deadlineMay 28, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities