Critical severity9.8NVD Advisory· Published Apr 26, 2022· Updated Jun 17, 2026
CVE-2022-29806
CVE-2022-29806
Description
ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contributes to exploitability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:zoneminder:zoneminder:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:zoneminder:zoneminder:*:*:*:*:*:*:*:*range: <1.36.13
- (no CPE)
- (no CPE)range: <1.36.13
Patches
Vulnerability mechanics
References
5- github.com/ZoneMinder/zoneminder/commit/9fee64b62fbdff5bf5ece1d617f1f53c7b1967cbnvdPatchThird Party Advisory
- packetstormsecurity.com/files/166980/ZoneMinder-Language-Settings-Remote-Code-Execution.htmlnvdExploitThird Party Advisory
- krastanoel.com/cve/2022-29806nvdExploitThird Party Advisory
- forums.zoneminder.com/viewtopic.phpnvdRelease NotesVendor Advisory
- github.com/ZoneMinder/zoneminder/releases/tag/1.36.13nvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.