Impact
motionEye’s ActionHandler.post() lacked authentication checks, allowing unauthenticated HTTP POST requests to /action/<camera_id>/<action> on installations older than 0.44.0. Attackers could trigger snapshot, record_start, record_stop, and, if configured, PTZ, alarm, lighting, and other scripted actions, potentially enabling remote manipulation of cameras or server‑side requests to external camera services. This behavior corresponds to the CWE‑862 “Missing Authorization” weakness and enables unauthorized camera control without credentials.
Affected Systems
All installations of motionEye from the motioneye‑project running a version older than 0.44.0 are affected. Versions prior to 0.44.0 expose the vulnerable endpoint on any platform that hosts the web interface. The 0.44.0 release restores authentication and removes the flaw.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. An attacker only needs access to the web interface to send a POST request to the exposed endpoint; no exploitation prerequisites beyond network connectivity are specified. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread public exploitation at present. Nevertheless, unauthorized camera control can compromise surveillance integrity, potentially revealing sensitive premises or disabling monitoring functions.
OpenCVE Enrichment
Github GHSA