Vulnerability record · CVE-2018-9276 · published 2 July 2018
CVE-2018-9276: PRTG Network Monitor OS Command Injection via Malformed Parameters
Paessler · Prtg Network Monitor
PRTG Network Monitor before 18.2.39 contains an OS command injection flaw (CWE-78) reachable through malformed parameters in sensor or notification management. An authenticated attacker with System Administrator web console privileges can execute arbitrary OS commands on the PRTG server and on managed devices. The flaw is remotely reachable over the network and is listed in CISA's Known Exploited Vulnerabilities catalog.
Description
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows authenticated remote OS command execution with high confidentiality, integrity and availability impact, is in CISA KEV with a very high EPSS score, and public exploits exist, though it requires prior administrative access.
What it is
PRTG Network Monitor before 18.2.39 contains an OS command injection flaw (CWE-78) reachable through malformed parameters in sensor or notification management. An authenticated attacker with System Administrator web console privileges can execute arbitrary OS commands on the PRTG server and on managed devices. The flaw is remotely reachable over the network and is listed in CISA's Known Exploited Vulnerabilities catalog.
Impact
An attacker gains arbitrary OS command execution with the privileges of the PRTG service on the server and on monitored devices. This can lead to full compromise of the monitoring host and lateral movement into monitored infrastructure.
Attack surface
Reached over the network via the PRTG web console (CVSS vector AV:N); the attacker must already hold administrative privileges (PR:H) and no user interaction is required (UI:N). Exploitation occurs through malformed parameters in sensor or notification management requests.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2025-02-04, indicating real-world exploitation, and EPSS gives a 30-day probability of 0.86996 (99.7th percentile). Multiple public exploit references exist, including Exploit-DB 46527 and Packet Storm entries. No ransomware campaign use is documented in the record.
What to do
- Upgrade PRTG Network Monitor to 18.2.39 or later; this is the primary fix.
- If immediate patching is not possible, apply the vendor mitigations referenced in the CISA KEV required action or discontinue use of the product.
- Restrict and audit access to the PRTG System Administrator web console, limiting it to trusted administrators and networks.
- Place the PRTG web interface behind network segmentation and strong authentication to reduce exposure.
- Monitor for and review any unexpected changes to sensors, notifications, or device configurations.
Detection
- Review PRTG web server and application logs for malformed or anomalous parameters in sensor and notification management requests.
- Monitor for unexpected child processes spawned by the PRTG service (e.g., cmd.exe, /bin/sh) on the PRTG server and monitored devices.
- Alert on administrative logins to the PRTG console from unusual source IPs or at unusual times.
- Hunt for outbound connections or command-and-control traffic originating from the PRTG server or managed devices.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-9276 to the Known Exploited Vulnerabilities catalog on 4 February 2025 as "Paessler PRTG Network Monitor OS Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 25 February 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/148334/PRTG-Command-Injection.html | ExploitMitigationThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/161183/PRTG-Network-Monitor-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/archive/1/542103/100/0/threaded | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/46527/ | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/148334/PRTG-Command-Injection.html | ExploitMitigationThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/161183/PRTG-Network-Monitor-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/archive/1/542103/100/0/threaded | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/46527/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-9276 | US Government Resource |
Track CVE-2018-9276 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-9276), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.