Record summary

CVE-2018-19410 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template. CISA lists CVE-2018-19410 in KEV.

Description

PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user can craft an HTTP request and override attributes of the 'include' directive in /public/login.htm and perform a Local File Inclusion attack, by including /api/addusers and executing it. By providing the 'id' and 'users' parameters, an unauthenticated attacker can create a user with read-write privileges (including administrator).

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Feb 4, 2025 · CISA
VulnCheck KEV
Listed · Feb 4, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationActive
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 4, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CISAVersion data not supplied

Proofs of concept

1

Repository PoCs

GitHubhimash/CVE-2018-19410-POCRepository PoCby himashStars: 3Not analyzed2 files

2.5 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALPRTG Network Monitor - Local File InclusionCVSS 9.8

PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user can craft an HTTP request and override attributes of the 'include' directive in /public/login.htm and perform a Local File Inclusion attack, by including /api/addusers and executing it. By providing the 'id' and 'users' parameters, an unauthenticated attacker can create a user with read-write privileges (including administrator).

Impact

Unauthenticated attackers can create administrator users with full privileges via local file inclusion, leading to complete compromise of the monitoring system and access to network infrastructure.

Remediation

Upgrade to PRTG Network Monitor version 18.2.40.1683 or later and ensure the /public directory is properly secured.

AuthorsDhiyaneshDK
Template tagscvecve2018prtglfikevvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:paessler:prtg_network_monitor:*:*:*:*:*:*:*:*
Shodan: http.favicon.hash:"-655683626"
Shodan: http.title:"prtg"
FOFA: icon_hash=-655683626
FOFA: title="prtg"
Google: intitle:"prtg"

Source: ProjectDiscovery

References

3