Motioneye Project maintains a focused video surveillance and motion-detection application that operates across embedded systems and Linux platforms, with vulnerability exposure centered on web-interface input handling and system command execution pathways. The recurring weakness classes—including output encoding failures, input validation gaps, OS command injection, insecure defaults, and missing authentication controls—reflect the application's role bridging user input to underlying system configuration and media capture functions. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Motioneye Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-60787HIGH MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration | Oct 3, 2025 | 7.2 | 62 | NO | YES |
CVE-2022-25568HIGH MotionEye v0.42.1 and below allows attackers to access sensitive information via a GET request to /config/list. To exploit this vulnerability, a regular user password must be uncon | Mar 24, 2022 | 7.5 | 38 | NO | YES |
CVE-2021-44255HIGH Authenticated remote code execution in MotionEye <= 0.42.1 and MotioneEyeOS <= 20200606 allows a remote attacker to upload a configuration backup file containing a malicious python | Jan 31, 2022 | 7.2 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Motioneye Project.
Media articles that mention a CVE ID that affects a product developed by Motioneye Project — matched by CVE ID, not by vendor name.