CVE-2024-11120: GeoVision Devices OS Command Injection Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2025-05-07. EPSS: 28.4% chance of exploitation in the next 30 days.

Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.

Affected products

  • GeoVision Gv-Dsp Lpr Firmware: affected versions not specified
  • GeoVision Gv-VS11 Firmware: affected versions not specified
  • GeoVision Gv-VS12 Firmware: affected versions not specified
  • GeoVision Gvlx 4 Firmware: affected versions not specified

Published 2024-11-15. Last modified 2026-06-17.