Vulnerability detail
Enriched intelligence for a single CVE
High
CVE-2018-9276
PUBLISHEDAn issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with...
- Vendor
- Paessler AG
- Product
- PRTG Network Monitor
- Published
- Jul 02, 2018
- EPSS
- —
Description
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios.
CVSS scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:S/C:C/I:C/A:C
Exploitation status
Exploited in the wild
Recorded 2025-02-04 00:00:00 UTC · Source
SSVC decision points
- Exploitation
- active
- Automatable
- No
- Technical impact
- total
Known exploited vulnerability sources
Catalogues that list this CVE as a known exploited vulnerability.
| Source | Added |
|---|---|
| CISA | Feb 04, 2025 |
Scanner integrations
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/prtg_authenticated_rce.rb | Apr 28, 2025 |
Potential proof of concepts
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2021-07-29 09:08:18 UTC · 0 stars
CVE-2018-9276 PRTG < 18.2.39 Reverse Shell (Python3 support)
github · Created 2021-01-02 09:08:42 UTC · 0 stars
github · Created 2019-03-31 08:51:07 UTC · 36 stars
CVE-2018-9276 PRTG < 18.2.39 Authenticated Command Injection (Reverse Shell)
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel
-
Detected by Metasploit