S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-25568 Scanner

CVE-2022-25568 scanner - Information Disclosure vulnerability in MotionEye

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-25568
7.5
CVSS

MotionEye v0.42.1 and below allows attackers to access sensitive information via a GET request to /config/list. To exploit this vulnerability, a regular user password must be unconfigured.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

MotionEye is a popular, open-source software used for monitoring and surveillance through network cameras. It's widely adopted by individuals and organizations for its ease of setup and comprehensive feature set, including motion detection, web interface, and video recording capabilities. MotionEye is often used in home security systems, small to medium enterprise security solutions, and by hobbyists for various monitoring projects. The software allows users to manage multiple cameras through a single interface, enhancing security and monitoring efficiency. Its versatility and compatibility with various camera types and operating systems make it a preferred choice for DIY surveillance systems.

The Information Disclosure vulnerability in MotionEye, identified as CVE-2022-25568, allows unauthorized access to sensitive configuration details through a simple GET request. This vulnerability exposes critical information such as passwords for upload and network services without requiring authentication. It poses a significant risk as attackers can exploit this vulnerability to gain insights into the surveillance system's setup, potentially leading to further attacks or unauthorized access to the network. This vulnerability underscores the importance of secure configuration and the need for regular software updates.

The vulnerability is specifically found in the /config/list endpoint of MotionEye versions 0.42.1 and below. By sending a GET request to this endpoint, an attacker can retrieve a JSON response containing sensitive information, including but not limited to, upload_password and network_password. This endpoint is not adequately protected, allowing unauthenticated access to critical configuration details. The lack of required authentication for accessing this endpoint demonstrates a significant oversight in the access control mechanisms implemented within the software.

Exploitation of this vulnerability can lead to several adverse outcomes. Attackers could gain access to the surveillance system, manipulate camera feeds, or disable the surveillance entirely. Additionally, access to network and upload passwords could allow attackers to infiltrate further into the network, leading to data breaches, unauthorized access to other systems, and potentially, remote code execution. The disclosure of sensitive information undermines the integrity and confidentiality of the surveillance system, putting personal and organizational security at risk.

By leveraging the security scanning capabilities of S4E, users can proactively identify and mitigate vulnerabilities like CVE-2022-25568 in their MotionEye setups. Our platform offers comprehensive Cyber Threat Exposure Management services, enabling users to secure their digital assets effectively. By becoming a member, you gain access to a suite of tools designed to detect configuration errors, vulnerabilities, and other cybersecurity threats. Ensure the security of your surveillance systems and protect your network from potential attacks with our advanced scanning solutions.

 

References

Solution Advice
  1. Upgrade MotionEye to the latest version available beyond 0.42.1 to mitigate this vulnerability.
  2. Ensure that all default passwords are changed to strong, unique passwords.
  3. Regularly review and update MotionEye configurations to secure access to sensitive endpoints.
  4. Implement network-level security measures, such as firewalls and access control lists, to restrict unauthorized access to the MotionEye interface.
  5. Conduct regular security assessments of your surveillance system to identify and address vulnerabilities promptly.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.