Junglewise Threat Intelligence

CVE-2018-9276: Paessler PRTG Network Monitor OS Command Injection Vulnerability

CVE-2018-9276 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2025-02-04

Technologies: Paessler PRTG Network Monitor. Vendors: Paessler.

Executive brief

Paessler PRTG Network Monitor contains an OS command injection vulnerability in its sensor and notification management components. An authenticated attacker with administrative privileges can execute arbitrary commands on the server or connected devices by sending malformed parameters through the PRTG System Administrator web console.

Affected products

  • Paessler PRTG Network Monitor before 18.2.39

Timeline

  • 2018-06-26: disclosed: Initial public disclosure via Packet Storm
  • 2025-02-04: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) Catalog
  • 2025-02-04: exploited: CISA confirmed exploitation in the wild

Related threats