CVE-2024-6047Active Exploitation(geovision / gv-bx130)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for geovision gv-bx130 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.

5.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-05-28. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gv-bx130
  • gv-bx130_firmware
  • gv-bx1500
  • gv-bx1500_firmware

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
gv-bx130gv-bx130_firmwaregv-bx1500gv-bx1500_firmwaregv-cb220gv-cb220_firmwaregv-dsp_lprgv-dsp_lpr_firmwaregv-ebl1100gv-ebl1100_firmware

3 versions affected across 40 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-04: 2PoC Mentioned / Linked · 2026-04-04: 1Active Exploitation · 2026-04-04: 2Technical Details · 2026-04-04: 104-04
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Threat@THREATCHAIN
    Active Exploitation

    🚨 BREAKING: Boatnet (LZRD) — Fresh Mirai botnet samples hitting IoT devices RIGHT NOW We just indexed 3 new variants targeting GeoVision cameras via CVE-2024-6047. ARM + x86. UPX-packed. 72% AV detection. Full IOCs + attack chain + defense guide: https://threatchain.io/boatnet-mirai-lzrd-botnet-2026 Search any hash free on ThreatChain 🔍 #infosec #malware #IoT #Mirai #threatintel #cybersecurity

    Post summary

    The tweet reports real‑time exploitation of CVE-2024-6047 on GeoVision cameras by Boatnet (LZRD) with fresh Mirai botnet samples and IOCs provided, and no patch or false‑positive claim is mentioned.

    1000075
    15 followersView on X
  • Threat@THREATCHAIN
    Active Exploitation

    IOCs for your blocklist: SHA256: 5bf2ef67e14876189cc28e342a7815ee9cb93ef9ff10110d5673ee2e31524844 12f96d5034d19f76f8e7d8ad46aecdbc40a0c188e7a3a05725559b2f93326e14 47454f90133eedfab3342836209ddadc9a6156933cbded9736443de00868070e Exploited CVEs: CVE-2024-6047, CVE-2024-11120 Target: GeoVision /DateSetting.cgi endpoint Family: Mirai/LZRD Triage score: 10/10 Look up any hash → https://threatchain.io

    Post summary

    The post lists blocklist hashes and notes that CVE-2024-6047 and CVE-2024-11120 are being exploited against GeoVision’s DateSetting.cgi; it provides no further technical details or mitigation guidance.

    0000059
    15 followersView on X
CPE platform detail41 entries

41 of 41 entries

PartVendorProductVersionTarget SWTarget HW
HWgeovisiongv-bx130---
OSgeovisiongv-bx130_firmware---
HWgeovisiongv-bx1500---
OSgeovisiongv-bx1500_firmware---
HWgeovisiongv-cb220---
OSgeovisiongv-cb220_firmware---
HWgeovisiongv-dsp_lpr2.0--
OSgeovisiongv-dsp_lpr_firmware---
HWgeovisiongv-ebl1100---
OSgeovisiongv-ebl1100_firmware---
HWgeovisiongv-efd1100---
OSgeovisiongv-efd1100_firmware---
HWgeovisiongv-fd2410---
OSgeovisiongv-fd2410_firmware---
HWgeovisiongv-fd3400---
OSgeovisiongv-fd3400_firmware---
HWgeovisiongv-fe3401---
OSgeovisiongv-fe3401_firmware---
HWgeovisiongv-fe420---
OSgeovisiongv-fe420_firmware---
HWgeovisiongv-gm8186_vs14---
OSgeovisiongv-gm8186_vs14_firmware---
HWgeovisiongv-vs03---
OSgeovisiongv-vs03_firmware---
HWgeovisiongv-vs04a---
OSgeovisiongv-vs04a_firmware---
HWgeovisiongv-vs04h---
OSgeovisiongv-vs04h_firmware---
HWgeovisiongv-vs14---
OSgeovisiongv-vs14_firmware---
HWgeovisiongv-vs21600---
OSgeovisiongv-vs21600_firmware---
HWgeovisiongv-vs2410---
OSgeovisiongv-vs2410_firmware---
HWgeovisiongv-vs2800---
OSgeovisiongv-vs2800_firmware---
HWgeovisiongv-vs2820---
OSgeovisiongv-vs2820_firmware---
HWgeovisiongvlx_42.0--
HWgeovisiongvlx_43.0--
OSgeovisiongvlx_4_firmware---

Explore more