← Vulnerability feed

Vulnerability record · CVE-2013-0232 · published 20 March 2013

CVE-2013-0232: ZoneMinder Video Server command injection via shell metacharacters

Zoneminder · Zoneminder

ZoneMinder Video Server 1.24.0, 1.25.0 and earlier pass unsanitized input into shell commands in includes/functions.php. The runState parameter in packageControl and the key or command parameters in setDeviceStatusX10 allow shell metacharacters to be injected. This lets an unauthenticated remote attacker run arbitrary commands on the server.

7.5 CVSS 2.0 High EPSS 48% · top 1.2%
7.5CVSS 2.0 base score
48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) runState parameter in the packageControl function; or (2) key or (3) command parameter in the setDeviceStatusX10 function.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityUnauthenticated remote command execution with public exploit code and very high EPSS score, though not in KEV.

What it is

ZoneMinder Video Server 1.24.0, 1.25.0 and earlier pass unsanitized input into shell commands in includes/functions.php. The runState parameter in packageControl and the key or command parameters in setDeviceStatusX10 allow shell metacharacters to be injected. This lets an unauthenticated remote attacker run arbitrary commands on the server.

Impact

An attacker can execute arbitrary operating system commands with the privileges of the ZoneMinder web server process. That gives full control of the host, including access to camera feeds and stored video.

Attack surface

Reachable over the network through the ZoneMinder web interface; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is 0.47895 (98.8th percentile) and references include an Exploit tag plus an Exploit-DB entry, indicating public exploit code exists.

What to do

  • Upgrade ZoneMinder to a version later than 1.25.0 that fixes the command injection, or apply the vendor/Debian security update (DSA-2640).
  • If patching is not possible, restrict network access to the ZoneMinder web interface to trusted hosts only.
  • Run the ZoneMinder web service under a low-privilege account with no shell access.
  • Review and remove any unnecessary X10 or package control functionality exposed to untrusted networks.

Detection

  • Monitor web server logs for requests to ZoneMinder endpoints containing shell metacharacters (;, |, &, $(), backticks) in runState, key, or command parameters.
  • Alert on unexpected child processes spawned by the web server user (e.g., sh, bash, curl, wget).
  • Use file integrity monitoring on the ZoneMinder web root and system binaries to catch post-exploitation changes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-0232 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-3882Zoneminder code injection vulnerabilityUnspecified "Command Injection" vulnerability in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary commands via (1) the exec…EPSS 3.5%9.8CVE-2025-65791Zoneminder os command injection vulnerabilityZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user input directly to the exec() f…EPSS 1.7%9.8CVE-2024-43360Zoneminder sql injection vulnerabilityZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability.…EPSS 6.2%9.8CVE-2023-26035ZoneMinder snapshot action missing authorization leads to RCEZoneMinder versions before 1.36.33 and 1.37.33 lack a permissions check on the snapshot action, which accepts an id meant to fetch an existing monito…EPSS 80%analysed9.8CVE-2023-26036Zoneminder untrusted search path vulnerabilityZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior …EPSS 0.90%9.8CVE-2023-26037Zoneminder sql injection vulnerabilityZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior …EPSS 0.61%9.8CVE-2022-29806ZoneMinder path traversal in language setting enables remote code executionZoneMinder before 1.36.13 allows remote code execution through an invalid language value, with a path traversal weakness (CWE-22) that lets an attack…EPSS 67%analysed9.8CVE-2019-8423Zoneminder sql injection vulnerabilityZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2013-0232), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.