CVE-2024-11120Active Exploitation(geovision / gv-dsp_lpr)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (6 mentions)

Immediate actions

  • Prioritize remediation for geovision gv-dsp_lpr systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-05-28. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gv-dsp_lpr
  • gv-dsp_lpr_firmware
  • gv-vs11
  • gv-vs11_firmware

Threat summary

  • Active exploitation appears in 7 classified signals
  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 7 signals
  • Peaked at 6 mentions on most recent observed day (2026-05-02)
  • 7 total mentions across 2 days

Affected systems

Vendors
Products
gv-dsp_lprgv-dsp_lpr_firmwaregv-vs11gv-vs11_firmwaregv-vs12gv-vs12_firmwaregvlx_4gvlx_4_firmware

3 versions affected across 8 products

Deep dive

Activity timeline7 mentions / 2d
02356Mentions · 2026-04-04: 1Mentions · 2026-05-02: 6Active Exploitation · 2026-04-04: 1Active Exploitation · 2026-05-02: 604-0405-02
Signal classification1 categories
Active Exploitation
7100.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-041
Active Exploitation1
2026-05-026
Active Exploitation6
Full discourse7 posts
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:14 UTC: Thread live on @lyrie_ai. What happened CISA added CVE-2024-11120 to the Known Exploited Vulnerabilities (KEV) catalog on 2025-05-07, signaling active exploitation in the wild CISA KEV.

    Post summary

    CISA added CVE‑2024‑11120 to its Known Exploited Vulnerabilities catalog, indicating it is currently being used in the wild.

    2000037
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:00 UTC: CVE-2024-11120 disclosed. CISA: CVE-2024-11120 added to Known Exploited Vulnerabilities — GeoVision Multiple Devices What happened CISA added CVE-2024-11120 to the Known Exploited Vulnerabilities (KEV) catalog on 2025-05-07, signaling active exploitation in the…

    Post summary

    CISA has listed CVE‑2024‑11120 as a known exploited vulnerability, indicating that it is actively being exploited in the wild on GeoVision devices.

    1001050
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:11 UTC: GPT-5 enrichment complete. 738 words. 3 citations. What happened CISA added CVE-2024-11120 to the Known Exploited Vulnerabilities (KEV) catalog on 2025-05-07, signaling active exploitation in the wild CISA KEV.

    Post summary

    CISA listed CVE-2024-11120 in the KEV catalog on 2025‑05‑07, confirming it is being exploited in the wild.

    1000036
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    03:00 UTC: First exploit attempt in the wild. What happened CISA added CVE-2024-11120 to the Known Exploited Vulnerabilities (KEV) catalog on 2025-05-07, signaling active exploitation in the wild CISA KEV.

    Post summary

    CISA has listed CVE‑2024‑11120 in its Known Exploited Vulnerabilities catalog, confirming that the vulnerability is being actively exploited in the wild.

    1000032
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:03 UTC: Lyrie Sentinel flagged it. What happened CISA added CVE-2024-11120 to the Known Exploited Vulnerabilities (KEV) catalog on 2025-05-07, signaling active exploitation in the wild CISA KEV.

    Post summary

    CISA has listed CVE-2024-11120 in its Known Exploited Vulnerabilities catalog, indicating it is actively exploited in the wild.

    1000034
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2024-11120-multiple-devices #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The snippet points to a research article suggesting CVE-2024-11120 is being actively exploited across multiple devices, but it lacks specific exploitation or patch details.

    0000029
    152 followersView on X
  • Threat@THREATCHAIN
    Active Exploitation

    IOCs for your blocklist: SHA256: 5bf2ef67e14876189cc28e342a7815ee9cb93ef9ff10110d5673ee2e31524844 12f96d5034d19f76f8e7d8ad46aecdbc40a0c188e7a3a05725559b2f93326e14 47454f90133eedfab3342836209ddadc9a6156933cbded9736443de00868070e Exploited CVEs: CVE-2024-6047, CVE-2024-11120 Target: GeoVision /DateSetting.cgi endpoint Family: Mirai/LZRD Triage score: 10/10 Look up any hash → https://threatchain.io

    Post summary

    The post announces that CVE-2024-6047 and CVE-2024-11120 have been actively exploited against GeoVision DateSetting.cgi endpoints by a Mirai/LZRD family operator, providing hashes for blocklisting.

    0000059
    15 followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
HWgeovisiongv-dsp_lpr3.0--
OSgeovisiongv-dsp_lpr_firmware---
HWgeovisiongv-vs11---
OSgeovisiongv-vs11_firmware---
HWgeovisiongv-vs12---
OSgeovisiongv-vs12_firmware---
HWgeovisiongvlx_42.0--
HWgeovisiongvlx_43.0--
OSgeovisiongvlx_4_firmware---

Explore more