EIP-2026-114642
PRE-CVEZoneMinder Snapshots < 1.37.33 - Unauthenticated RCE
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114642. PoCs published by Ravindu Wickramasinghe.
AI-analyzed exploit summary This exploit leverages an unauthenticated command injection vulnerability in ZoneMinder's snapshot functionality by injecting a malicious payload into the 'monitor_ids[0][Id]' parameter. It fetches a CSRF token, constructs a reverse shell payload, and executes it via a crafted POST request.
Description
ZoneMinder Snapshots < 1.37.33 - Unauthenticated RCE
Exploits (1)
This exploit leverages an unauthenticated command injection vulnerability in ZoneMinder's snapshot functionality by injecting a malicious payload into the 'monitor_ids[0][Id]' parameter. It fetches a CSRF token, constructs a reverse shell payload, and executes it via a crafted POST request.