CVE-2024-11120
Description
Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.
Summary dbcve.org
OS command injection vulnerability in EOL GeoVision devices allowing unauthenticated remote attackers to inject and execute arbitrary system commands. Actively exploited in the wild.
Mitigation
Since GeoVision devices are End-of-Life with no patch available, immediately isolate affected devices from the internet, place them behind network segmentation, and consider replacement with supported hardware. Implement additional monitoring for Indicators of Compromise.