CVE-2025-60787General(motioneye_project / motioneye)

LOWCVSS 7.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration files, allowing remote authenticated attackers with admin access to achieve code execution when Motion is restarted.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-78CWE-116

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • motioneye

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Technical details provided in 4 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-02-14); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Products
motioneye

2 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-14: 1Mentions · 2026-04-30: 1Mentions · 2026-06-23: 1Mentions · 2026-07-13: 1PoC Mentioned / Linked · 2026-02-14: 1PoC Mentioned / Linked · 2026-07-13: 1Technical Details · 2026-02-14: 1Technical Details · 2026-04-30: 1Technical Details · 2026-06-23: 1Technical Details · 2026-07-13: 102-1404-3006-2307-13
Signal classification3 categories
General
250.0%
Disclosure
125.0%
PoC
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-141
Disclosure1
2026-04-301
General1
2026-06-231
General1
2026-07-131
PoC1
Full discourse4 posts
  • Red Secure Tech Ltd.@redsecuretech
    Disclosure

    CVE-2025-60787 in motionEye ≤0.43.1b4 allows authenticated RCE by bypassing client-side validation and injecting shell metacharacters into config values. https://redsecuretech.co.uk/blog/post/motioneye-0-43-1b4-rce-via-config-file-injection/928 #Cybersecurity #CVE #motionEye #RCE #IoTSecurity #Vulnerability #ThreatIntel https://t.co/yEC0ZpJtBT

    Post summary

    The tweet announces CVE-2025-60787 affecting motionEye (≤0.43.1b4), describing an authenticated RCE via configuration file injection and links to a blog post that likely contains further technical details.

    0101032
    38 followersView on X
  • 𝙷𝚞𝚐𝚘 𝙲𝚎𝚜𝚊𝚛 𝚁𝚊𝚖𝚘𝚜@HugoCesarRamos
    General

    Ruptura del Aislamiento de Capas (Privilege Escalation) Interceptación de Tráfico Lateral (Data Exfiltration) Explotación de RCE (CVE-2025-60787) https://t.co/zIoyiw5SGU

    Post summary

    The tweet mentions CVE-2025-60787 as a remote code execution vulnerability with potential layer isolation break and lateral traffic interception, but provides no PoC, exploit tool, patch, or evidence of real‑world exploitation.

    00010600
    3 followersView on X
  • sckull@sckull_
    PoC

    HackTheBox - CCTV 💥 SQL Injection en ZoneMinder 🚀 motionEye (CVE-2025-60787) para root https://sckull.github.io/posts/cctv/

    Post summary

    The post announces an SQL injection flaw in ZoneMinder and a CVE‑2025‑60787 SQL injection in motionEye that can lead to root, with a link to a proof‑of‑concept.

    0000060
    178 followersView on X
  • DailyCVE@dailycve
    General

    🔴 motionEye, Multi-Stage Chain RCE, #CVE-2025-60787 / #CVE-2026-31978 (Critical) -DC-Jun2026-597 https://dailycve.com/motioneye-multi-stage-chain-rce-cve-2025-60787-cve-2026-31978-critical-dc-jun2026-597/

    Post summary

    The note announces critical multi-stage RCE vulnerabilities (CVE-2025-60787 and CVE-2026-31978) affecting motionEye, without providing exploit details or remediation guidance.

    0000049
    216 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appmotioneye_projectmotioneye0.42.1--
Appmotioneye_projectmotioneye0.43.1--
Appmotioneye_projectmotioneye0.43.1--
Appmotioneye_projectmotioneye0.43.1--
Appmotioneye_projectmotioneye0.43.1--

Explore more