CVE-2021-25296
KEV PoC ×3moderate1Authenticated OS Command Injection in Nagios XI 5.7.5 Windows WMI Wizard
CISA: Nagios XI OS Command Injection
Nagios XI 5.7.5 contains an OS command injection flaw in the Windows WMI configuration wizard (windowswmi.inc.php), where authenticated user-controlled input is not properly sanitized. A single crafted HTTP request from an authenticated low-privileged user is enough to execute arbitrary operating system commands on the Nagios XI server, giving attackers full compromise of confidentiality, integrity, and availability (CVSS 8.8). Organizations running Nagios XI 5.7.5, particularly internet-facing monitoring servers, are affected. The flaw is publicly documented with proof-of-concept exploits and a Metasploit module, and it was added to CISA's Known Exploited Vulnerabilities Catalog on 2022-01-18 with a 72.2% EPSS exploitation probability. Reported campaigns have turned vulnerable Nagios XI servers into cryptocurrency miners, and multi-exploit botnet activity (e.g., Mirai variants) has also targeted this class of flaws.
What to do: Upgrade Nagios XI from 5.7.5 to the latest vendor-supplied release per Nagios' instructions, as required by the CISA KEV entry. Until patched, restrict access to the Nagios XI web interface and configuration wizards and review access logs for requests to the windowswmi wizard endpoint. Also check affected servers for unexpected processes or outbound connections that could indicate cryptomining or botnet payloads.
| Nagios XI | xi-5.7.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.
- Affected
- Nagios Nagios XI
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- nagios
- Products
- nagios xi
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news5 stories
IoT Under Siege: The Anatomy of the Latest Mirai Campaign Leveraging Multiple IoT Exploits
Unit 42 tracks a Mirai botnet campaign exploiting over 20 IoT vulnerabilities in routers, cameras and DVRs to build DDoS botnets since March 2023.
Since March 2023, Unit 42 has tracked threat actors exploiting more than 20 IoT vulnerabilities to spread a Mirai botnet variant, first seen downloading payloads from zvub.us on March 14, 2023. Exploited flaws span CVE-2023-1389 (TP-Link Archer), CVE-2022-30525 (Zyxel), CVE-2022-31499 (Nortek) and many router, camera and DVR bugs. The variant decrypts configuration strings with an XOR key derived from 0xDEADBEEF and lacks built-in credential brute forcing, so spreading relies on manual operator exploitation. Two campaigns observed since October 2022 share infrastructure and near-identical samples.