CVE-2025-60787 is an OS Command Injection vulnerability affecting MotionEye v0.43.1b4 and earlier, specifically within configuration parameters like image_file_name. This flaw allows remote authenticated attackers with admin privileges to achieve code execution by injecting unsanitized input into Motion configuration files, which is then executed upon Motion's restart. With a CVSS score of 7.2 HIGH, this vulnerability presents a significant risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. Exploit code is publicly available, including a Metasploit module and an ExploitDB entry, and it has garnered substantial community discussion, indicating active interest in its exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.42.1CPE matchmatch criteria | cpe:2.3:a:motioneye_project:motioneye:0.42.1:*:*:*:*:*:*:* | ||
0.43.1CPE matchmatch criteria | cpe:2.3:a:motioneye_project:motioneye:0.43.1:beta1:*:*:*:*:*:* | ||
0.43.1CPE matchmatch criteria | cpe:2.3:a:motioneye_project:motioneye:0.43.1:beta2:*:*:*:*:*:* | ||
0.43.1CPE matchmatch criteria | cpe:2.3:a:motioneye_project:motioneye:0.43.1:beta3:*:*:*:*:*:* | ||
0.43.1CPE matchmatch criteria | cpe:2.3:a:motioneye_project:motioneye:0.43.1:beta4:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.