Sploitus

CVE-2025-60787

24 known exploits for CVE-2025-60787

MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration files, allowing remote authenticated attackers with admin access to achieve code execution when Motion is restarted.

Affected products
Motioneye
Motioneye Project Motioneye
= 0.42.1, 0.43.1
CVSS 3.1
7.2 HIGH
EPSS
18.5% (97th percentile)
Weakness
CWE-20, CWE-116, CWE-78
NVD status
Modified
Published
2025-10-03
CVE-2025-60787 at NVD
Authoritative description, scoring and affected products

24 known exploits for CVE-2025-60787

Proof-of-concept code and exploit modules indexed by Sploitus

CVE-2025-60787_PoC
2026-09-07 KitPloitKITPLOIT
CVE-2025-60787
2026-09-07 KitPloitKITPLOIT
CVE-2025-60787
2026-09-05 KitPloitKITPLOIT
CVE-2025-60787-MotionEye-RCE
2026-09-03 KitPloitKITPLOIT
CVE-2025-60787-POC
2026-09-02 KitPloitKITPLOIT
CVE-2025-60787
2026-09-02 KitPloitKITPLOIT
CVE-2025-60787
2026-09-01 KitPloitKITPLOIT
CVE-2025-60787-Detection-motionEye-RCE-via-Config-Injection
2026-09-01 KitPloitKITPLOIT
Exploit for Improper Input Validation in Motioneye_Project Motioneye
2026-07-10 ozcanpngGITHUB
ffensive-playbook
2026-04-16 TryzubRageGITHUB
ofensive-playbook
2026-04-16 TryzubRageGITHUB
Exploit for OS Command Injection in Motioneye_Project Motioneye
2026-03-14 agent-skywalkerGITHUB
πŸ“„ Vvveb CMS 1.0.5 Command Injection
2026-03-11 indoushkaPACKETSTORMPHP
Exploit for OS Command Injection in Motioneye_Project Motioneye
2026-03-08 gunzf0xGITHUB
Exploit for OS Command Injection in Motioneye_Project Motioneye
2026-03-08 lil0xplorerGITHUB
Exploit for OS Command Injection in Motioneye_Project Motioneye
2026-03-07 RohitberiwalaGITHUB
Exploit for OS Command Injection in Motioneye_Project Motioneye
2026-02-28 GarethMSheldonGITHUB
πŸ“„ motionEye 0.43.1b4 Remote Command Injection
2026-02-18 indoushkaPACKETSTORM
motionEye 0.43.1b4 - RCE
2026-02-11 prabhatEXPLOITDB
πŸ“„ motionEye 0.43.1b4 Remote Code Execution
2026-02-11 prabhatverma47PACKETSTORM
πŸ“„ MotionEye Frontend 0.43.1b4 Command Injection
2026-02-04 indoushkaPACKETSTORMPHP
πŸ“„ MotionEye Frontend 0.43.1b4 Remote Code Execution
2025-10-10 Maksim Rogov, prabhatverma47PACKETSTORMRuby
Exploit for CVE-2025-60787
2025-10-03 prabhatverma47GITHUB
Remote Code Execution Vulnerability in MotionEye Frontend (CVE-2025-60787)
2025-09-09 Maksim Rogov, prabhatverma47METASPLOITRuby