ZeroHour

CVE-2021-25296

KEV PoC ×3moderate1

Authenticated OS Command Injection in Nagios XI 5.7.5 Windows WMI Wizard

CISA: Nagios XI OS Command Injection

CVSS 3.1
8.8 high
EPSS
72%p99
Published
()
KEV added
AI analysis

Nagios XI 5.7.5 contains an OS command injection flaw in the Windows WMI configuration wizard (windowswmi.inc.php), where authenticated user-controlled input is not properly sanitized. A single crafted HTTP request from an authenticated low-privileged user is enough to execute arbitrary operating system commands on the Nagios XI server, giving attackers full compromise of confidentiality, integrity, and availability (CVSS 8.8). Organizations running Nagios XI 5.7.5, particularly internet-facing monitoring servers, are affected. The flaw is publicly documented with proof-of-concept exploits and a Metasploit module, and it was added to CISA's Known Exploited Vulnerabilities Catalog on 2022-01-18 with a 72.2% EPSS exploitation probability. Reported campaigns have turned vulnerable Nagios XI servers into cryptocurrency miners, and multi-exploit botnet activity (e.g., Mirai variants) has also targeted this class of flaws.

What to do: Upgrade Nagios XI from 5.7.5 to the latest vendor-supplied release per Nagios' instructions, as required by the CISA KEV entry. Until patched, restrict access to the Nagios XI web interface and configuration wizards and review access logs for requests to the windowswmi wizard endpoint. Also check affected servers for unexpected processes or outbound connections that could indicate cryptomining or botnet payloads.

Affected
Nagios XIxi-5.7.5
Estimated exposure
moderate≈10,000+ deployments (thousands of internet-exposed Nagios XI servers visible in public scans) — Nagios XI is a widely adopted enterprise monitoring platform deployed across tens of thousands of organizations, and public internet scans regularly surface thousands of exposed Nagios XI instances, making roughly 10,000+ total deployments…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.

CISA Known Exploited Vulnerability
Affected
Nagios Nagios XI
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
nagios
Products
nagios xi
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

IoT Under Siege: The Anatomy of the Latest Mirai Campaign Leveraging Multiple IoT Exploits

Unit 42 tracks a Mirai botnet campaign exploiting over 20 IoT vulnerabilities in routers, cameras and DVRs to build DDoS botnets since March 2023.

Since March 2023, Unit 42 has tracked threat actors exploiting more than 20 IoT vulnerabilities to spread a Mirai botnet variant, first seen downloading payloads from zvub.us on March 14, 2023. Exploited flaws span CVE-2023-1389 (TP-Link Archer), CVE-2022-30525 (Zyxel), CVE-2022-31499 (Nortek) and many router, camera and DVR bugs. The variant decrypts configuration strings with an XOR key derived from 0xDEADBEEF and lacks built-in credential brute forcing, so spreading relies on manual operator exploitation. Two campaigns observed since October 2022 share infrastructure and near-identical samples.

Palo Alto Unit 42 · 29d agoMalware in the wildCVE-2019-12725CVE-2019-17621CVE-2019-20500+13 CVEs