CVE-2018-19410
KEVlargeUnauthenticated LFI in Paessler PRTG Enables Admin Account Creation
CISA: Paessler PRTG Network Monitor Local File Inclusion Vulnerability
CVE-2018-19410 is a local file inclusion (LFI) flaw in the PRTG Network Monitor web login page (/public/login.htm) where an attacker can override the 'include' directive via a crafted HTTP request. By directing the include to /api/addusers and supplying the 'id' and 'users' parameters, a remote, unauthenticated attacker triggers that API and creates a new user with read-write privileges, including full administrator. Effectively, this gives an unauthenticated remote attacker persistent, privileged access to the monitoring server's console, with visibility into monitored infrastructure and the ability to alter monitoring configuration. Any PRTG Network Monitor deployment running a version prior to 18.2.40.1683 is affected, with risk concentrated on instances whose web interface is reachable by attackers (internet-exposed consoles, or consoles reachable from compromised internal networks). The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-04 with a federal patch deadline of 2025-02-25, and its EPSS score of 97.9% (100th percentile) indicates near-certain likelihood of exploitation within 30 days, though no public proof-of-concept is known.
What to do: Upgrade PRTG Network Monitor to version 18.2.40.1683 or later (current releases include the fix; CISA's required action is to apply vendor mitigations or discontinue use). Until patched, restrict access to the PRTG web console (e.g., firewall it to trusted management networks and avoid internet exposure). Review the web server logs for unauthenticated requests to /public/login.htm with manipulated 'include' parameters or calls to /api/addusers, and audit existing PRTG user accounts for unauthorized administrator accounts created via this flaw.
| paessler prtg network monitor | before 18.2.40.1683 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user can craft an HTTP request and override attributes of the 'include' directive in /public/login.htm and perform a Local File Inclusion attack, by including /api/addusers and executing it. By providing the 'id' and 'users' parameters, an unauthenticated attacker can create a user with read-write privileges (including administrator).
- Affected
- Paessler PRTG Network Monitor
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- paessler
- Products
- prtg network monitor
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H