LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-6047: GeoVision Devices OS Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 7, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 28, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-6047 to its Known Exploited Vulnerabilities catalog on May 7, 2025, with a federal patch deadline of May 28, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacted products could be…

CVE-2024-6047 is an OS command injection vulnerability affecting multiple GeoVision devices. A remote, unauthenticated attacker can inject and execute arbitrary system commands on the device. This matters because successful exploitation can give an attacker full control of the device, enabling further network access, data theft, or disruption. Some impacted products may already be end-of-life or end-of-service, which raises the risk that no vendor fix will be available.

Defenders should treat this as a high-priority issue for any GeoVision hardware still in production environments and confirm all details against the vendor advisory and CISA guidance.

How it works

The vulnerability is classified as CWE-78 (OS Command Injection). In this class of flaw, user-supplied input reaches a system command interpreter without proper sanitization or validation. An attacker can craft input that appends or substitutes shell commands, causing the device to execute them with the privileges of the vulnerable process.

According to the CISA summary, the attack requires no authentication and can be performed remotely. Once the injected command runs, the attacker can perform any action the device’s operating system permits, such as reading configuration files, establishing reverse shells, or modifying device behavior. Exact injection points and request formats are not detailed in the public summary and must be confirmed against the vendor advisory; do not assume a particular interface or protocol is the sole vector.

Am I affected? How to find it in your systems

GeoVision devices commonly appear as network video recorders, IP cameras, and related surveillance appliances. They are often deployed on corporate, industrial, or multi-site networks and may be reachable from the internet or from less-trusted internal segments.

Confirm exact model and firmware applicability only from the vendor advisory; do not rely on third-party version lists.

How to remediate

The primary remediation path is to apply the mitigations or updates published by GeoVision. CISA’s required action is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for any cloud-connected services, or discontinue use of the product if mitigations are unavailable.

Document the change and retain evidence of the applied mitigation for audit purposes.

If you can't patch immediately

When an immediate update or replacement is not feasible, reduce exposure with compensating controls while you arrange a permanent fix.

These steps lower risk but do not eliminate it; schedule full remediation as soon as resources allow.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities frequently lead to broader compromises. Although ransomware use of CVE-2024-6047 is not documented, any successful command injection can result in credential theft, lateral movement, or data exfiltration. Review device and network logs for signs of compromise, rotate credentials that may have been stored on or used by the devices, and consider a free exposure scan of organizational email addresses against known breach data sets to identify previously leaked accounts that attackers might reuse.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedGeoVision · Multiple Devices
WeaknessCWE-78
Added to CISA KEVMay 7, 2025
Federal patch deadlineMay 28, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities