PoC Index

CVE-2018-9276

KEVHIGH 9.0EPSS 87.2%

An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios.

CVSS v3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
9.0 HIGHAV:N/AC:L/Au:S/C:C/I:C/A:C
EPSS
87.17% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2025-02-04
Published
2018-07-02
Updated
2025-10-21

Proof-of-concept exploits (8)

Metasploit modules (1)

ExploitDB entries (1)

References

Related