Executive brief
Multiple end-of-life GeoVision IP camera devices contain an OS command injection vulnerability due to improper filtering of user input. A remote, unauthenticated attacker can exploit this to execute arbitrary system commands on the affected device.
Affected products
- GeoVision GV-BX130 firmware all versions (EOL)
- GeoVision GV-BX1500 firmware all versions (EOL)
- GeoVision GV-CB220 firmware all versions (EOL)
- GeoVision GV-EBL1100 firmware all versions (EOL)
- GeoVision GV-EFD1100 firmware all versions (EOL)
- GeoVision GV-FD2410 firmware all versions (EOL)
- GeoVision GV-FD3400 firmware all versions (EOL)
- GeoVision GV-FE3401 firmware all versions (EOL)
Timeline
- 2025-05-07: disclosed
- 2025-05-07: kev added: Added to CISA KEV catalog due to active exploitation by Mirai botnet.