ZeroHour

CVE-2018-19410

KEVlarge

Unauthenticated LFI in Paessler PRTG Enables Admin Account Creation

CISA: Paessler PRTG Network Monitor Local File Inclusion Vulnerability

CVSS 3.1
9.8 critical
EPSS
98%p100
Published
()
KEV added
AI analysis

CVE-2018-19410 is a local file inclusion (LFI) flaw in the PRTG Network Monitor web login page (/public/login.htm) where an attacker can override the 'include' directive via a crafted HTTP request. By directing the include to /api/addusers and supplying the 'id' and 'users' parameters, a remote, unauthenticated attacker triggers that API and creates a new user with read-write privileges, including full administrator. Effectively, this gives an unauthenticated remote attacker persistent, privileged access to the monitoring server's console, with visibility into monitored infrastructure and the ability to alter monitoring configuration. Any PRTG Network Monitor deployment running a version prior to 18.2.40.1683 is affected, with risk concentrated on instances whose web interface is reachable by attackers (internet-exposed consoles, or consoles reachable from compromised internal networks). The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-04 with a federal patch deadline of 2025-02-25, and its EPSS score of 97.9% (100th percentile) indicates near-certain likelihood of exploitation within 30 days, though no public proof-of-concept is known.

What to do: Upgrade PRTG Network Monitor to version 18.2.40.1683 or later (current releases include the fix; CISA's required action is to apply vendor mitigations or discontinue use). Until patched, restrict access to the PRTG web console (e.g., firewall it to trusted management networks and avoid internet exposure). Review the web server logs for unauthenticated requests to /public/login.htm with manipulated 'include' parameters or calls to /api/addusers, and audit existing PRTG user accounts for unauthorized administrator accounts created via this flaw.

Affected
paessler prtg network monitorbefore 18.2.40.1683
Estimated exposure
largelikely on the order of hundreds of thousands of installations, with at least tens of thousands of web consoles potentially reachable (estimate; no count in… — PRTG is a widely deployed on-premises network monitoring product with an install base Paessler has long reported in the hundreds of thousands, but the flaw is only remotely exploitable where the PRTG web console is exposed, so the directly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user can craft an HTTP request and override attributes of the 'include' directive in /public/login.htm and perform a Local File Inclusion attack, by including /api/addusers and executing it. By providing the 'id' and 'users' parameters, an unauthenticated attacker can create a user with read-write privileges (including administrator).

CISA Known Exploited Vulnerability
Affected
Paessler PRTG Network Monitor
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
paessler
Products
prtg network monitor
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news