ZeroHour

CVE-2018-9276

KEV PoC ×3large

Authenticated OS Command Injection in Paessler PRTG Network Monitor < 18.2.39

CISA: Paessler PRTG Network Monitor OS Command Injection Vulnerability

CVSS 3.1
7.2 high
EPSS
87%p100
Published
()
KEV added
AI analysis

Paessler PRTG Network Monitor versions before 18.2.39 contain an OS command injection flaw (CWE-78) in the PRTG System Administrator web console. An attacker with administrative access to that console can trigger arbitrary command execution on both the PRTG server and on monitored devices by sending malformed parameters in sensor or notification management scenarios, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.2, high privileges required, no user interaction). Any organization running PRTG Network Monitor older than 18.2.39 is affected, although exploitation requires valid administrative access to the console. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-02-04, confirming active in-the-wild exploitation, with public proof-of-concept references (Exploit-DB 46527 and two PacketStorm entries) and an EPSS probability of 87% of exploitation within 30 days. Defenders running unpatched PRTG instances, especially consoles reachable from the internet, should treat this as actively targeted.

What to do: Upgrade PRTG Network Monitor to 18.2.39 or later (any current release includes the fix); per CISA's KEV entry, apply vendor mitigations or discontinue use of unpatched versions by the February 25, 2025 deadline. Inventory PRTG servers — particularly consoles exposed to the internet — restrict System Administrator console access to trusted users and networks, and audit sensor and notification configurations and logs for tampering or unexpected command execution.

Affected
paessler prtg network monitorAll versions before 18.2.39 (fixed in 18.2.39)
Estimated exposure
largeTens of thousands of on-premises installations / hundreds of thousands of users historically affected (estimate; no authoritative count in the data) — Basis: PRTG is a widely deployed Windows-based network-monitoring platform used heavily by SMBs and MSPs, with a vendor-cited user base in the hundreds of thousands and thousands to tens of thousands of consoles visible in public internet…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios.

CISA Known Exploited Vulnerability
Affected
Paessler PRTG Network Monitor
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
paessler
Products
prtg network monitor
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news