← Vulnerability feed

Vulnerability record · CVE-2022-29806 · published 26 April 2022

CVE-2022-29806: ZoneMinder path traversal in language setting enables remote code execution

Zoneminder · Zoneminder

ZoneMinder before 1.36.13 allows remote code execution through an invalid language value, with a path traversal weakness (CWE-22) that lets an attacker create a debug log file at an arbitrary pathname. The flaw is remotely reachable without authentication and carries a critical CVSS score of 9.8, so unpatched ZoneMinder instances are at serious risk.

9.8 CVSS 3.1 Critical EPSS 67% · top 0.7% CWE-22 · Path traversal
9.8CVSS 3.1 base score, v2 7.5
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contributes to exploitability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication, no user interaction, and public exploit references make this a critical remote code execution risk.

What it is

ZoneMinder before 1.36.13 allows remote code execution through an invalid language value, with a path traversal weakness (CWE-22) that lets an attacker create a debug log file at an arbitrary pathname. The flaw is remotely reachable without authentication and carries a critical CVSS score of 9.8, so unpatched ZoneMinder instances are at serious risk.

Impact

An unauthenticated attacker can execute arbitrary code on the ZoneMinder host, leading to full compromise of confidentiality, integrity and availability. The ability to write a debug log to an arbitrary pathname supports the exploit chain.

Attack surface

The vulnerability is network-reachable (AV:N) with no privileges (PR:N) and no user interaction (UI:N), based on the CVSS vector and the description of remote code execution via an invalid language. No authentication is required to reach the flaw.

Exploitation

Public exploit references are present (Packet Storm and a third-party writeup tagged Exploit), and EPSS is high at 0.67128 (99.267th percentile), though CISA KEV does not list it. This indicates active interest and likely weaponization, but the record does not confirm in-the-wild exploitation.

What to do

  • Upgrade ZoneMinder to version 1.36.13 or later, which contains the patch commit 9fee64b62fbdff5bf5ece1d617f1f53c7b1967cb.
  • If immediate patching is not possible, restrict network access to the ZoneMinder web interface to trusted networks or place it behind an authenticated reverse proxy.
  • Monitor and restrict filesystem write permissions for the ZoneMinder process so it cannot create files at arbitrary paths.
  • Review debug log configuration and ensure log paths are fixed and not influenced by user-supplied language or locale input.

Detection

  • Search ZoneMinder logs for requests containing invalid or unexpected language parameters that may indicate traversal attempts.
  • Monitor for unexpected debug log files created outside the configured log directory.
  • Alert on outbound network connections or process execution from the ZoneMinder service account that are not part of normal operation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-29806 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-3882Zoneminder code injection vulnerabilityUnspecified "Command Injection" vulnerability in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary commands via (1) the exec…EPSS 3.5%9.8CVE-2025-65791Zoneminder os command injection vulnerabilityZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user input directly to the exec() f…EPSS 1.7%9.8CVE-2024-43360Zoneminder sql injection vulnerabilityZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability.…EPSS 6.2%9.8CVE-2023-26035ZoneMinder snapshot action missing authorization leads to RCEZoneMinder versions before 1.36.33 and 1.37.33 lack a permissions check on the snapshot action, which accepts an id meant to fetch an existing monito…EPSS 80%analysed9.8CVE-2023-26036Zoneminder untrusted search path vulnerabilityZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior …EPSS 0.90%9.8CVE-2023-26037Zoneminder sql injection vulnerabilityZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior …EPSS 0.61%9.8CVE-2019-8423Zoneminder sql injection vulnerabilityZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.EPSS 1.6%9.8CVE-2019-8424Zoneminder sql injection vulnerabilityZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2022-29806), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.