CVE-2021-25296

HIGH KEV NUCLEI

Nagios XI xi-5.7.5 - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-25296 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added January 18, 2022. EIP tracks 1 public exploit from researchers including Matthew Mathur, including a Metasploit module exploits/linux/http/nagios_xi_configwizards_authenticated_rce. A Nuclei detection template is also available.

AI-analyzed exploit summary This Metasploit module exploits CVE-2021-25296, CVE-2021-25297, and CVE-2021-25298, which are OS command injection vulnerabilities in Nagios XI's configuration wizards. It allows authenticated users to execute arbitrary commands on vulnerable Nagios XI versions (5.5.6 to 5.7.5).

Description

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.

Exploits (1)

metasploit WORKING POC EXCELLENT
by Matthew Mathur · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/nagios_xi_configwizards_authenticated_rce.rb

This Metasploit module exploits CVE-2021-25296, CVE-2021-25297, and CVE-2021-25298, which are OS command injection vulnerabilities in Nagios XI's configuration wizards. It allows authenticated users to execute arbitrary commands on vulnerable Nagios XI versions (5.5.6 to 5.7.5).

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Nagios XI versions 5.5.6 to 5.7.5
Auth required
Prerequisites: Valid Nagios XI user credentials · Access to the Nagios XI web interface
devstral-2 · analyzed Apr 23, 2026 Full analysis →

Nuclei Templates (1)

Nagios XI 5.5.6-5.7.5 - Authenticated Remote Command Injection
HIGHVERIFIEDby k0pak4
Shodan: title:"Nagios XI" || http.title:"nagios xi"
FOFA: title="nagios xi" || app="nagios-xi"

Scores

CVSS v3 8.8
EPSS 0.9329
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2022-01-18
VulnCheck KEV 2021-06-01
InTheWild.io 2021-03-16
ENISA EUVD EUVD-2021-12196
Status published
Products (1)
nagios/nagios_xi 5.5.6 - 5.7.5
Published Feb 15, 2021
KEV Added Jan 18, 2022
Tracked Since Feb 18, 2026