CVE-2018-9276
HIGH KEVPaessler Prtg Network Monitor < 18.2.39 - OS Command Injection
Title source: ruleDescription
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios.
Exploits (8)
nomisec
WORKING POC
by AC8999 · poc
https://github.com/AC8999/PRTG-Network-Monitor-18.2.38---Authenticated-Remote-Code-Execution-CVE-2018-9276
metasploit
WORKING POC
EXCELLENT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/prtg_authenticated_rce.rb
References (5)
Scores
CVSS v3
7.2
EPSS
0.8689
EPSS Percentile
99.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2025-02-04
VulnCheck KEV
2025-02-04
ENISA EUVD
EUVD-2018-20870
CWE
CWE-78
Status
published
Products (1)
paessler/prtg_network_monitor
< 18.2.39
Published
Jul 02, 2018
KEV Added
Feb 04, 2025
Tracked Since
Feb 18, 2026