CVE-2025-65791

CRITICAL

ZoneMinder 1.36.34 - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-65791. PoCs published by rishavand1.

AI-analyzed exploit summary The repository provides a detailed technical analysis of CVE-2025-65791, a command injection vulnerability in ZoneMinder v1.36.34. It includes vulnerability details, attack scenarios, and mitigation recommendations but lacks functional exploit code.

Description

ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user input directly to the exec() function. NOTE: this is disputed by the Supplier because there is no unsanitized user input to web/views/image.php.

Exploits (1)

nomisec WRITEUP
by rishavand1 · poc
https://github.com/rishavand1/CVE-2025-65791

The repository provides a detailed technical analysis of CVE-2025-65791, a command injection vulnerability in ZoneMinder v1.36.34. It includes vulnerability details, attack scenarios, and mitigation recommendations but lacks functional exploit code.

Classification
Writeup 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: ZoneMinder v1.36.34
No auth needed
Prerequisites: Access to the vulnerable ZoneMinder instance
devstral-2 · analyzed May 04, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0028
EPSS Percentile 51.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
zoneminder/zoneminder 1.36.34
Published Feb 18, 2026
Tracked Since Feb 18, 2026