Junglewise Threat Intelligence

CVE-2018-19410: Paessler PRTG Network Monitor Local File Inclusion Vulnerability

CVE-2018-19410 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-02-04

Technologies: Paessler PRTG Network Monitor. Vendors: Paessler.

Executive brief

Paessler PRTG Network Monitor contains a local file inclusion (LFI) vulnerability in the 'include' directive of /public/login.htm. A remote, unauthenticated attacker can exploit this by including /api/addusers to create new user accounts with read-write or administrator privileges.

Affected products

  • Paessler PRTG Network Monitor before 18.2.40.1683

Timeline

  • 2018-11-21: disclosed: NVD Published Date
  • 2025-02-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats