Executive brief
PRTG Network Monitor is an infrastructure monitoring platform that tracks servers, networks, and applications across IT environments. A vulnerability in the HTTP XML/REST Sensor component allows authenticated users to write arbitrary files to the probe system, potentially compromising system integrity and enabling further attacks.
Technical details
The vulnerability is an arbitrary file write flaw in certain EXE sensors, specifically affecting the HTTP XML/REST Value sensor. It requires an authenticated user with access to configure sensors to exploit. An attacker can craft malicious sensor configurations to write arbitrary files to the probe system where PRTG is running, potentially leading to code execution or system compromise. The vulnerability was addressed and fixed in PRTG version 23.1.82, released in May 2023. Users should upgrade to the patched version immediately.
Affected products
- Paessler PRTG Network Monitor before 23.1.82
Timeline
- 2023-05: disclosed: Vulnerability fixed in PRTG 23.1.82
- 2026-09-14: advisory