Vulnerability record · CVE-2022-29806 · published 26 April 2022
CVE-2022-29806: ZoneMinder path traversal in language setting enables remote code execution
Zoneminder · Zoneminder
ZoneMinder before 1.36.13 allows remote code execution through an invalid language value, with a path traversal weakness (CWE-22) that lets an attacker create a debug log file at an arbitrary pathname. The flaw is remotely reachable without authentication and carries a critical CVSS score of 9.8, so unpatched ZoneMinder instances are at serious risk.
Description
ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contributes to exploitability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, no user interaction, and public exploit references make this a critical remote code execution risk.
What it is
ZoneMinder before 1.36.13 allows remote code execution through an invalid language value, with a path traversal weakness (CWE-22) that lets an attacker create a debug log file at an arbitrary pathname. The flaw is remotely reachable without authentication and carries a critical CVSS score of 9.8, so unpatched ZoneMinder instances are at serious risk.
Impact
An unauthenticated attacker can execute arbitrary code on the ZoneMinder host, leading to full compromise of confidentiality, integrity and availability. The ability to write a debug log to an arbitrary pathname supports the exploit chain.
Attack surface
The vulnerability is network-reachable (AV:N) with no privileges (PR:N) and no user interaction (UI:N), based on the CVSS vector and the description of remote code execution via an invalid language. No authentication is required to reach the flaw.
Exploitation
Public exploit references are present (Packet Storm and a third-party writeup tagged Exploit), and EPSS is high at 0.67128 (99.267th percentile), though CISA KEV does not list it. This indicates active interest and likely weaponization, but the record does not confirm in-the-wild exploitation.
What to do
- Upgrade ZoneMinder to version 1.36.13 or later, which contains the patch commit 9fee64b62fbdff5bf5ece1d617f1f53c7b1967cb.
- If immediate patching is not possible, restrict network access to the ZoneMinder web interface to trusted networks or place it behind an authenticated reverse proxy.
- Monitor and restrict filesystem write permissions for the ZoneMinder process so it cannot create files at arbitrary paths.
- Review debug log configuration and ensure log paths are fixed and not influenced by user-supplied language or locale input.
Detection
- Search ZoneMinder logs for requests containing invalid or unexpected language parameters that may indicate traversal attempts.
- Monitor for unexpected debug log files created outside the configured log directory.
- Alert on outbound network connections or process execution from the ZoneMinder service account that are not part of normal operation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/166980/ZoneMinder-Language-Settings-Remote-Code-Execution.html | ExploitThird Party Advisory |
| https://forums.zoneminder.com/viewtopic.php?t=31638 | Release NotesVendor Advisory |
| https://github.com/ZoneMinder/zoneminder/commit/9fee64b62fbdff5bf5ece1d617f1f53c7b1967cb | PatchThird Party Advisory |
| https://github.com/ZoneMinder/zoneminder/releases/tag/1.36.13 | Release NotesThird Party Advisory |
| https://krastanoel.com/cve/2022-29806 | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/166980/ZoneMinder-Language-Settings-Remote-Code-Execution.html | ExploitThird Party Advisory |
| https://forums.zoneminder.com/viewtopic.php?t=31638 | Release NotesVendor Advisory |
| https://github.com/ZoneMinder/zoneminder/commit/9fee64b62fbdff5bf5ece1d617f1f53c7b1967cb | PatchThird Party Advisory |
| https://github.com/ZoneMinder/zoneminder/releases/tag/1.36.13 | Release NotesThird Party Advisory |
| https://krastanoel.com/cve/2022-29806 | ExploitThird Party Advisory |
Track CVE-2022-29806 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-29806), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.