Executive brief
Multiple end-of-life (EOL) GeoVision devices contain an OS command injection vulnerability. Remote, unauthenticated attackers can exploit this flaw to execute arbitrary system commands on the affected hardware.
Affected products
- GeoVision GV-DSP LPR firmware - (EOL)
- GeoVision GV-VS11 firmware - (EOL)
- GeoVision GV-VS12 firmware - (EOL)
- GeoVision GVLX 4 firmware - (EOL)
Timeline
- 2024-11-14: disclosed: Initial NVD publication date
- 2025-05-07: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog
- 2025-05-07: exploited: Reported as actively exploited in the wild by Akamai and CISA