Vulnerability record · CVE-2013-0232 · published 20 March 2013
CVE-2013-0232: ZoneMinder Video Server command injection via shell metacharacters
Zoneminder · Zoneminder
ZoneMinder Video Server 1.24.0, 1.25.0 and earlier pass unsanitized input into shell commands in includes/functions.php. The runState parameter in packageControl and the key or command parameters in setDeviceStatusX10 allow shell metacharacters to be injected. This lets an unauthenticated remote attacker run arbitrary commands on the server.
Description
includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) runState parameter in the packageControl function; or (2) key or (3) command parameter in the setDeviceStatusX10 function.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
critical priorityUnauthenticated remote command execution with public exploit code and very high EPSS score, though not in KEV.
What it is
ZoneMinder Video Server 1.24.0, 1.25.0 and earlier pass unsanitized input into shell commands in includes/functions.php. The runState parameter in packageControl and the key or command parameters in setDeviceStatusX10 allow shell metacharacters to be injected. This lets an unauthenticated remote attacker run arbitrary commands on the server.
Impact
An attacker can execute arbitrary operating system commands with the privileges of the ZoneMinder web server process. That gives full control of the host, including access to camera feeds and stored video.
Attack surface
Reachable over the network through the ZoneMinder web interface; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.47895 (98.8th percentile) and references include an Exploit tag plus an Exploit-DB entry, indicating public exploit code exists.
What to do
- Upgrade ZoneMinder to a version later than 1.25.0 that fixes the command injection, or apply the vendor/Debian security update (DSA-2640).
- If patching is not possible, restrict network access to the ZoneMinder web interface to trusted hosts only.
- Run the ZoneMinder web service under a low-privilege account with no shell access.
- Review and remove any unnecessary X10 or package control functionality exposed to untrusted networks.
Detection
- Monitor web server logs for requests to ZoneMinder endpoints containing shell metacharacters (;, |, &, $(), backticks) in runState, key, or command parameters.
- Alert on unexpected child processes spawned by the web server user (e.g., sh, bash, curl, wget).
- Use file integrity monitoring on the ZoneMinder web root and system binaries to catch post-exploitation changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-0232 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-0232), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.