Executive brief
Paessler PRTG Network Monitor contains an OS command injection vulnerability in its sensor and notification management components. An authenticated attacker with administrative privileges can execute arbitrary commands on the server or connected devices by sending malformed parameters through the PRTG System Administrator web console.
Affected products
- Paessler PRTG Network Monitor before 18.2.39
Timeline
- 2018-06-26: disclosed: Initial public disclosure via Packet Storm
- 2025-02-04: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) Catalog
- 2025-02-04: exploited: CISA confirmed exploitation in the wild