
Authenticated RCE exploit for MotionEye <= 0.43.1b4 via client-side validation bypass on the image_file_name field. Includes reverse shell payload delivery.
| Flag | Description |
|---|
-t | Target host/URL (defaults to port 8765) |
-u | Username (default: admin) |
-p | Password - same value you type in the GUI / found in motion.conf |
-lh | Your attacker IP |
-lp | Listener port |
--camera-id | Camera ID (auto-detected if omitted) |