CVE-2014-6433: Gopro Hero

High severity, CVSS 10.0. EPSS: 3.3% chance of exploitation in the next 30 days.

gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary files via a the (1) a1 or (2) a2 parameter in a start action.

Affected products

  • Gopro Gopro Hero
  • Gopro Gopro Hero Firmware: version 3+ only

Published 2014-10-07. Last modified 2026-06-17.