CVE-2018-9276
KEVHIGH 9.0EPSS 87.2%
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios.
- CVSS v3.1
- 7.2 HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.2 HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 9.0 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C - EPSS
- 87.17% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2025-02-04
- Published
- 2018-07-02
- Updated
- 2025-10-21
Proof-of-concept exploits (8)
- http://packetstormsecurity.com/files/148334/PRTG-Command-Injection.html
- http://packetstormsecurity.com/files/161183/PRTG-Network-Monitor-Remote-Code-Execution.ht…
- A1vinSmith/CVE-2018-927618★ · 2022-12-22
- alvinsmith-eroad/CVE-2018-92760★ · 2021-07-29
- andyfeili/CVE-2018-92760★ · 2021-01-02
- backglass/exploit_prtg2★ · 2024-09-04
- wildkindcc/CVE-2018-927636★ · 2020-12-03
- AC8999/PRTG-Network-Monitor-18.2.38---Authenticated-Remote-Code-Execution-CVE-2018-9276