Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2024-6047
GeoVision EOL device - OS Command Injection
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H H 9.8 .1007 95.5 YES
AFFECTED
Product Versions Fixed
GV_DSP_LPR_V2 all – —
GV_IPCAMD_GV_BX1500 all – —
GV_IPCAMD_GV_CB220 all – —
GV_IPCAMD_GV_EBL1100 all – —
GV_IPCAMD_GV_EFD1100 all – —
GV_IPCAMD_GV_FD2410 all – —
GV_IPCAMD_GV_FD3400 all – —
GV_IPCAMD_GV_FE3401 all – —
GV_IPCAMD_GV_FE420 all – —
GV-VS14_VS14 all – —
+ 10 more
TIMELINE
Jun 17 Reserved by twcert
Jun 17 Published (CNA: twcert)
May 7 Added to CISA KEV, remediation due 2025-05-28
Description
Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| June 17, 2024 | Reserved | Reserved by twcert |
| June 17, 2024 | Published | Published (CNA: twcert) |
| May 7, 2025 | KEV ADDED | Added to CISA KEV, remediation due 2025-05-28 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2024-6047 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.