CVE-2018-9276

An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with...

Basic Information

CVE State
PUBLISHED
Reserved Date
April 04, 2018
Published Date
July 02, 2018
Last Updated
February 04, 2025
Vendor
n/a
Product
n/a
Description
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios.

CVSS Scores

CVSS v3.1

7.2 - HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0

9.0 -

Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

SSVC Information

Exploitation
active
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2025-02-04 00:00:00 UTC) Source
Proof of Concept Available
Yes (added 2021-07-29 09:08:18 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2025-02-04 00:00:00 UTC

Scanner Integrations

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

prtg_authenticated_rce

Type: metasploit • Created: Unknown

Metasploit module for CVE-2018-9276

alvinsmith-eroad/CVE-2018-9276

Type: github • Created: 2021-07-29 09:08:18 UTC • Stars: 0

CVE-2018-9276 PRTG < 18.2.39 Reverse Shell (Python3 support)

andyfeili/CVE-2018-9276

Type: github • Created: 2021-01-02 09:08:42 UTC • Stars: 0

wildkindcc/CVE-2018-9276

Type: github • Created: 2019-03-31 08:51:07 UTC • Stars: 36

CVE-2018-9276 PRTG < 18.2.39 Authenticated Command Injection (Reverse Shell)