CVE-2025-24367

HIGH

Cacti Graph Template authenticated RCE versions prior to 1.2.29

Title source: metasploit

Description

Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execution on the server. This vulnerability is fixed in 1.2.29.

Exploits (7)

nomisec WORKING POC 28 stars
by TheCyberGeek · poc
https://github.com/TheCyberGeek/CVE-2025-24367-Cacti-PoC
github WORKING POC 2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2025/CVE-2025-24367
nomisec WORKING POC 1 stars
by matesz44 · poc
https://github.com/matesz44/CVE-2025-24367
nomisec WORKING POC
by ShoshinMaster · poc
https://github.com/ShoshinMaster/CVE-2025-24367
nomisec WORKING POC
by SoftAndoWetto · poc
https://github.com/SoftAndoWetto/CVE-2025-24367-PoC-Cacti
nomisec WORKING POC
by r0tn3x · poc
https://github.com/r0tn3x/CVE-2025-24367
metasploit WORKING POC EXCELLENT
by chutchut, Jack Heysel · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/cacti_graph_template_rce.rb

Scores

CVSS v3 8.8
EPSS 0.9049
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-144
Status published
Products (1)
cacti/cacti < 1.2.29
Published Jan 27, 2025
Tracked Since Feb 18, 2026