ZoneMinder versions before 1.36.13 contain a remote code-execution vulnerability associated with processing an invalid language. The ability to create a debug log file at an arbitrary pathname contributes to exploitation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Python exploit (exploit.py) for CVE-2022-29806, a path traversal and privilege escalation vulnerability in ZoneMinder up to version 1.36.12. The exploit automates the process of writing a PHP reverse shell payload to the target's /tmp/proof.php file by abusing the application's logging configuration and language file inclusion features. It then triggers the payload by setting the default language to the malicious file, resulting in remote code execution as the web server user. The exploit requires the attacker to provide the target URL, their own IP, and a port for the reverse shell. The README provides usage instructions and context. The main attack vector is network-based, targeting the ZoneMinder web interface. The exploit is operational, providing a working reverse shell if the target is vulnerable.
This repository contains a single Metasploit module (zoneminder_lang_exec.rb) that exploits a remote code execution vulnerability (CVE-2022-29806) in ZoneMinder surveillance software versions before 1.36.13 and 1.37.11. The exploit leverages an arbitrary file write via the debug log file option and a path traversal in the language settings to write a PHP payload to a web-accessible directory. The module authenticates to the ZoneMinder web interface (default path: /zm/), leaks the installation directory, writes a PHP shell to the target, and triggers its execution by changing the language setting. The default payload is a PHP reverse shell, but any Metasploit-compatible PHP payload can be used. The exploit requires valid credentials and network access to the ZoneMinder web interface. The module also includes cleanup steps to restore the original configuration. The code is written in Ruby and is fully integrated into the Metasploit framework, making it weaponized and easy to use for attackers.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.