References https://github.com/motioneye-project/motioneye/issues/2292 https://pizzapower.me/2022/02/17/motioneye-config-info-disclosure/ https://pizzapower.me/2021/10/09/self-hosted-security-part-1-motioneye/ https://www.cvedetails.com/cve/CVE-2022-25568/ https://advisories.gitlab.com/pkg/pypi/motioneye/CVE-2022-25568/ https://github.com/motioneye-project/motioneye/issues/695 https://www.exploit-db.com/exploits/52481 https://avd.aliyun.com/detail?id=AVD-2022-25568
Related VulnerabilitiesPoC泛微E-cology10 /papi/passport/appnew/login/appLogin 未授权访问漏洞PoCNginxWebUI /adminPage/login/getAuth 命令执行漏洞PoCmarimo-unauth: motionEye Partial - Authentication BypassmotionEye /action/1/snapshot 权限绕过漏洞(CVE-2026-55863)motionEye /picture/ 目录遍历漏洞(CVE-2026-31978)motionEye /movie/1/playback 目录遍历漏洞(CVE-2026-55488)管家婆物联通 /Login/getLogin 默认口令漏洞创世13星零售商城系统 /Login/shangchuan 文件上传漏洞深信服运维安全管理系统 /fort/login/search_login 信息泄露漏洞WGCLOUD /login/login 默认口令漏洞Doccano /v1/auth/login/ 默认口令漏洞PoC杭州九麒科技-BigAnt即时通讯系统 /home/login/loginByToken 权限绕过漏洞Ilevia EVE X1 Server /login/login.php 默认口令漏洞(CVE-2025-34516)