CVE-2025-24367
HIGHCacti Graph Template authenticated RCE versions prior to 1.2.29
Title source: metasploitDescription
Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execution on the server. This vulnerability is fixed in 1.2.29.
Exploits (7)
nomisec
WORKING POC
28 stars
by TheCyberGeek · poc
https://github.com/TheCyberGeek/CVE-2025-24367-Cacti-PoC
github
WORKING POC
2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2025/CVE-2025-24367
nomisec
WORKING POC
by SoftAndoWetto · poc
https://github.com/SoftAndoWetto/CVE-2025-24367-PoC-Cacti
metasploit
WORKING POC
EXCELLENT
by chutchut, Jack Heysel · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/cacti_graph_template_rce.rb
Scores
CVSS v3
8.8
EPSS
0.9049
EPSS Percentile
99.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-144
Status
published
Products (1)
cacti/cacti
< 1.2.29
Published
Jan 27, 2025
Tracked Since
Feb 18, 2026