Botnet exploits GeoVision zero-day to install Mirai malware

Teilen:

A malware botnet is exploiting a zero-day vulnerability in end-of-life GeoVision devices to compromise and recruit them for likely DDoS or cryptomining attacks.

The flaw is tracked as CVE-2024-11120 and was discovered by Piort Kijewski of The Shadowserver Foundation. It is a critical severity (CVSS v3.1 score: 9.8) OS command injection problem, allowing unauthenticated attackers to execute arbitrary system commands on the device.

“Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device,” warns Taiwan’s CERT.

“Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.”

According to TWCERT, the vulnerability impacts the following device models:

  • GV-VS12: A 2-channel H.264 video server that converts analog video signals into digital streams for network transmission.
  • GV-VS11: A single-channel video server designed to digitize analog video for network streaming.
  • GV-DSP LPR V3: A Linux-based system dedicated to license plate recognition (LPR).
  • GV-LX4C V2 / GV-LX4C V3: Compact digital video recorders (DVRs) designed for mobile surveillance applications.

All of these models have reached the end of life and are no longer supported by the vendor, so no security updates are expected.

Threat monitoring platform The Shadowserver Foundation reports that approximately 17,000 GeoVision devices are exposed online and are vulnerable to the CVE-2024-11120 flaw.

Kijewski told BleepingComputer that the botnet appears to be a Mirai variant, which is usually used as part of DDoS platforms or to perform cryptomining.

Tweet

Most of the exposed devices (9,100) are based in the United States, followed by Germany (1,600), Canada (800), Taiwan (800), Japan (350), Spain (300), and France (250).

Location of exposed GeoVision devices
Location of exposed GeoVision devices
Source: The Shadowserver Foundation

In general, signs of botnet compromise include devices heating excessively, becoming slow or unresponsive, and having their configuration arbitrarily changed.

If you notice any of these symptoms, perform a device reset, change the default admin password to something strong, turn off remote access panels, and place the device behind a firewall.

Ideally, these devices should be replaced with actively supported models, but if that’s impossible, they should be isolated on a dedicated LAN or subnet and closely monitored.

Bill Toulas

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
6:52 pm, Feb. 3, 2025
Wetter-Symbol 7°C
L: 6° | H: 8°
broken clouds
Luftfeuchtigkeit: 91 %
Druck: 1024 mb
Wind: 6 mph S
Windböe: 8 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 69%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:35 am
Sonnenuntergang: 4:53 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
6° | 8°°C 0 mm 0% 5 mph 93 % 1024 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
5° | 10°°C 0.36 mm 36% 14 mph 93 % 1026 mb 0 mm/h
Mi. Feb. 05 9:00 pm
Wetter-Symbol
4° | 8°°C 0 mm 0% 8 mph 92 % 1043 mb 0 mm/h
Do. Feb. 06 9:00 pm
Wetter-Symbol
3° | 8°°C 0 mm 0% 9 mph 85 % 1045 mb 0 mm/h
Fr. Feb. 07 9:00 pm
Wetter-Symbol
2° | 7°°C 0 mm 0% 12 mph 93 % 1041 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
6° | 7°°C 0 mm 0% 5 mph 93 % 1024 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
5° | 6°°C 0 mm 0% 6 mph 93 % 1024 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
6° | 6°°C 0 mm 0% 7 mph 89 % 1023 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
6° | 6°°C 0 mm 0% 9 mph 93 % 1023 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
7° | 7°°C 0 mm 0% 10 mph 92 % 1023 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
9° | 9°°C 0 mm 0% 12 mph 78 % 1022 mb 0 mm/h
Tomorrow 3:00 pm
Wetter-Symbol
9° | 9°°C 0 mm 0% 14 mph 78 % 1021 mb 0 mm/h
Tomorrow 6:00 pm
Wetter-Symbol
10° | 10°°C 0 mm 0% 13 mph 79 % 1022 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€97,823.61
2.98%
Ethereum(ETH)
€2,674.92
-6.78%
XRP(XRP)
€2.61
5.62%
Fesseln(USDT)
€0.98
0.22%
Solana(SOL)
€206.46
5.77%
USDC(USDC)
€0.98
0.00%
Dogecoin(DOGE)
€0.266871
1.67%
Shiba Inu(SHIB)
€0.000016
1.36%
Pepe(PEPE)
€0.000011
-3.96%
Nach oben scrollen