CVE-2018-9276
KEV PoC ×3largeAuthenticated OS Command Injection in Paessler PRTG Network Monitor < 18.2.39
CISA: Paessler PRTG Network Monitor OS Command Injection Vulnerability
Paessler PRTG Network Monitor versions before 18.2.39 contain an OS command injection flaw (CWE-78) in the PRTG System Administrator web console. An attacker with administrative access to that console can trigger arbitrary command execution on both the PRTG server and on monitored devices by sending malformed parameters in sensor or notification management scenarios, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.2, high privileges required, no user interaction). Any organization running PRTG Network Monitor older than 18.2.39 is affected, although exploitation requires valid administrative access to the console. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-02-04, confirming active in-the-wild exploitation, with public proof-of-concept references (Exploit-DB 46527 and two PacketStorm entries) and an EPSS probability of 87% of exploitation within 30 days. Defenders running unpatched PRTG instances, especially consoles reachable from the internet, should treat this as actively targeted.
What to do: Upgrade PRTG Network Monitor to 18.2.39 or later (any current release includes the fix); per CISA's KEV entry, apply vendor mitigations or discontinue use of unpatched versions by the February 25, 2025 deadline. Inventory PRTG servers — particularly consoles exposed to the internet — restrict System Administrator console access to trusted users and networks, and audit sensor and notification configurations and logs for tampering or unexpected command execution.
| paessler prtg network monitor | All versions before 18.2.39 (fixed in 18.2.39) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios.
- Affected
- Paessler PRTG Network Monitor
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- paessler
- Products
- prtg network monitor
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H