CVE-2025-5965
moderateOS Command Injection in Centreon Infra Monitoring backup configuration
CVE-2025-5965 is an OS command injection flaw (CWE-78) in the backup configuration of the administration setup modules in Centreon Infra Monitoring (the on-premises web interface of Centreon's IT infrastructure monitoring platform, listed under CPE as Centreon Web). A user with high privileges on the web interface can concatenate custom instructions to the backup setup, and because these parameters are not properly neutralized before being passed to the operating system, arbitrary OS commands are executed when the backup jobs run. An attacker who already holds high-privilege (admin-level) access can therefore escalate from application administration to OS-level command execution on the monitoring server, with high impact on confidentiality, integrity, and availability. Deployments running the 24.04 branch before 24.04.19, the 24.10 branch before 24.10.15, or the 25.10 branch before 25.10.2 are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known, but the EPSS score of 28.6% (98th percentile) signals an elevated probability of exploitation within 30 days.
What to do: Upgrade Centreon Infra Monitoring to 24.04.19, 24.10.15, or 25.10.2 depending on your branch. Until patched, restrict high-privilege accounts on the web interface and review configured backup parameters for unexpected or injected shell commands. Because exploitation requires admin access, audit admin accounts, and inspect backup job logs for anomalous command execution or unexpected child processes spawned during backup runs.
| Centreon Infra Monitoring | from 24.04.0 before 24.04.19 |
| Centreon Infra Monitoring | from 24.10.0 before 24.10.15 |
| Centreon Infra Monitoring | from 25.10.0 before 25.10.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In the backup parameters, a user with high privilege is able to concatenate custom instructions to the backup setup. Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitoring (Backup configuration in the administration setup modules) allows OS Command Injection.This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.15, from 24.04.0 before 24.04.19.
- Vendors
- centreon
- Products
- centreon web
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.