← back
CVE-2022-25568

CVE-2022-25568

18Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 6.9%
exploitation probability
6.9%top 6% of all CVEs
observed exploitation
nono source reports it
MotionEye v0.42.1 and below allows attackers to access sensitive information via a GET request to /config/list. To exploit this vulnerability, a regular user password must be unconfigured.
Affected products
n/a · n/a