peter bassill · operator
$ cve CVE-2018-9276 JSON

CVE-2018-9276 KEV EXPLOIT

7.2
HIGH · CVSS 3.1 · EPSS 87% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2025-02-25.

Description

An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios.

Scoring

CVSS7.2 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS87% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-78
On CISA KEVyes — remediate by 2025-02-25
Public exploityes
Published2018-07-02
Last modified2026-06-17

CISA KEV

NamePaessler PRTG Network Monitor OS Command Injection Vulnerability
Added2025-02-04
Due2025-02-25
Vendor / productPaessler / PRTG Network Monitor
Ransomware usenone reported

Affected (1)

VendorProduct
paesslerprtg network monitor

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD