CVE-2018-9276

HIGH KEV

Paessler Prtg Network Monitor < 18.2.39 - OS Command Injection

Title source: rule

Description

An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios.

Exploits (8)

exploitdb WORKING POC
by M4LV0 · bashwebappswindows
https://www.exploit-db.com/exploits/46527
nomisec WORKING POC 36 stars
by wildkindcc · remote
https://github.com/wildkindcc/CVE-2018-9276
nomisec WORKING POC
by AC8999 · poc
https://github.com/AC8999/PRTG-Network-Monitor-18.2.38---Authenticated-Remote-Code-Execution-CVE-2018-9276
nomisec WORKING POC
by alvinsmith-eroad · remote
https://github.com/alvinsmith-eroad/CVE-2018-9276
nomisec WORKING POC
by andyfeili · poc
https://github.com/andyfeili/CVE-2018-9276
vulncheck_xdb WORKING POC
remote-auth
https://github.com/backglass/exploit_prtg
inthewild WORKING POC
poc
https://github.com/a1vinsmith/cve-2018-9276
metasploit WORKING POC EXCELLENT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/prtg_authenticated_rce.rb

Scores

CVSS v3 7.2
EPSS 0.8689
EPSS Percentile 99.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2025-02-04
VulnCheck KEV 2025-02-04
ENISA EUVD EUVD-2018-20870
CWE
CWE-78
Status published
Products (1)
paessler/prtg_network_monitor < 18.2.39
Published Jul 02, 2018
KEV Added Feb 04, 2025
Tracked Since Feb 18, 2026