🔴 CVE-2024-6047

Critical OS command injection vulnerability affecting multiple end-of-life GeoVision IP cameras and video servers. Unauthenticated attackers can execute arbitrary system commands remotely over the network with CVSS 9.8 severity.

← Back to Overview
HIGH_RISK
Risk Level
9.8
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2024-06-17

Added to CISA KEV: 2025-05-07 324 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-06-04)

CVE-2024-6047 is a critical command injection vulnerability affecting certain discontinued (End-of-Life) GeoVision IoT devices [1] [2].

Key Details
FeatureDescription
Vulnerability TypeCommand Injection [2]
ExploitationActive exploitation in the wild has been confirmed [2]
Threat ActorsExploited by Mirai-based IoT botnets [2]
RequirementsUnauthenticated, remote access; no user interaction required [1]
ImpactArbitrary system command execution and file writing with system-level privileges [3]
Patch StatusNo patch available (EOL devices) [1]
Analysis
  • Active Exploitation: The vulnerability has been actively exploited in the wild, notably by Mirai-based botnets seeking to compromise IoT devices [2]. It is often associated with similar command injection flaws in GeoVision devices, such as CVE-2024-11120 [2].
  • Attack Method: Attackers exploit the device's failure to properly filter user input for specific functionality. Because it is a remote, unauthenticated command injection, it allows attackers to gain control over the affected hardware without needing any interaction from a user [1].
  • Impact: Successful exploitation provides attackers with the ability to execute arbitrary system commands and write arbitrary files with system-level privileges, effectively granting them full control over the compromised device [3].
  • Patch/Mitigation: As the affected GeoVision devices are End-of-Life (EOL), no official patches are available [1]. The primary recommendation for such devices is to disconnect them from the internet or replace them with supported hardware.

Sources

  1. NVD - CVE-2024-6047

    An official website of the United States government Here's how you know ... National Vulnerability Database. Vulnerabilities. CVE-2024-6047 Detail. Unsupported When Assigned. Description. Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated…

  2. Here Comes Mirai: IoT Devices RSVP to Active Exploitation - Akamai

    See details and IOCs of Akamai SIRT's discovery of active exploitation of the command injection vulnerabilities CVE-2024-6047 and ... Certain discontinued GeoVision devices fail to properly filter user input for this parameter, which allows unauthenticated remote attackers to inject and execute arbi…

  3. CVE-2024-6047 - Exploits & Severity - Feedly

    Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can ... CVE-2024-6047 is a command injection vulnerability identified in discontinued GeoVision IoT devices, which has been actively exploited in the wild, as reported by…