
CVE-2025-60787 in motionEye ≤0.43.1b4 allows authenticated RCE by bypassing client-side validation and injecting shell metacharacters into config values. https://redsecuretech.co.uk/blog/post/motioneye-0-43-1b4-rce-via-config-file-injection/928 #Cybersecurity #CVE #motionEye #RCE #IoTSecurity #Vulnerability #ThreatIntel https://t.co/yEC0ZpJtBT
Post summary
The tweet announces CVE-2025-60787 affecting motionEye (≤0.43.1b4), describing an authenticated RCE via configuration file injection and links to a blog post that likely contains further technical details.



