A botnet used for DDoS attacks or cryptomining is exploiting a zero-day vulnerability in GeoVision that have reached their end-of-life.

Researchers at the Shadowserver Foundation observed that a botnet is exploiting this zero-day vulnerability in GeoVision EOL devices to compromise them.
See more: Samba AD vulnerability allows hackers to escalate privileges
The zero-day vulnerability , listed as CVE-2024-11120 (CVSS 9.8), is a pre-auth command injection vulnerability, discovered by the Shadowserver Foundation and confirmed with the help of TWCERT. It affects the following EoL products: GV-VS12, GV-VS11, GV-DSP_LPR_V3, GVLX 4 V2 and GVLX 4 V3.
The announcement from TWCERT states that “certain GeoVision EOL devices have an OS Command Injection vulnerability. Unauthenticated remote hackers can exploit this vulnerability to input and execute arbitrary commands on the device.” Furthermore, this vulnerability has already been exploited by hackers, as relevant reports show.

The botnet is used to carry out DDoS attacks or cryptomining. According to the Shadowserver Foundation, there are approximately 17,000 GeoVision devices exposed online and vulnerable to the zero-day CVE-2024-11120.
Read more: GorillaBot has emerged as the "king" of DDoS attacks
Most of these devices are located in the United States (9,179), followed by Germany (1,652), Taiwan (792) and Canada (784).
Source: securityaffairs
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
