CVE-2022-29806

CRITICAL

ZoneMinder < 1.36.13 - Remote Code Execution via Invalid Language Setting

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2022-29806. PoCs published by Sigm0n, krastanoel, including Metasploit module exploits/unix/webapp/zoneminder_lang_exec.

AI-analyzed exploit summary This is a functional exploit for CVE-2022-29806, targeting a path traversal vulnerability in ZoneMinder up to 1.36.12. It achieves RCE by manipulating debug log file paths and default language options to write and execute arbitrary PHP code.

Description

ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contributes to exploitability.

Exploits (2)

nomisec WORKING POC 3 stars
by Sigm0n · poc
https://github.com/Sigm0n/CVE-2022-29806

This is a functional exploit for CVE-2022-29806, targeting a path traversal vulnerability in ZoneMinder up to 1.36.12. It achieves RCE by manipulating debug log file paths and default language options to write and execute arbitrary PHP code.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: ZoneMinder up to 1.36.12
No auth needed
Prerequisites: Target URL · Attacker IP · Port for reverse shell
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by krastanoel · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/zoneminder_lang_exec.rb

This Metasploit module exploits a chained vulnerability in ZoneMinder (CVE-2022-29806) involving arbitrary file write via debug log manipulation and path traversal in language settings to achieve remote code execution. It authenticates, leaks the installation path, writes a PHP payload to a traversed path, and triggers execution by modifying language settings.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: ZoneMinder before 1.36.13 and before 1.37.11
Auth required
Prerequisites: Valid ZoneMinder credentials · Network access to the ZoneMinder web interface · PHP payload compatible with the target environment
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://forums.zoneminder.com/viewtopic.php?t=31638
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/ZoneMinder/zoneminder/releases/tag/1.36.13
Exploit, Third Party Advisory x_refsource_misc
https://krastanoel.com/cve/2022-29806

Scores

CVSS v3 9.8
EPSS 0.6632
EPSS Percentile 99.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22
Status published
Products (1)
zoneminder/zoneminder < 1.36.13
Published Apr 26, 2022
Tracked Since Feb 18, 2026