← Vulnerability feed

Vulnerability record · CVE-2018-9276 · published 2 July 2018

CVE-2018-9276: PRTG Network Monitor OS Command Injection via Malformed Parameters

Paessler · Prtg Network Monitor

PRTG Network Monitor before 18.2.39 contains an OS command injection flaw (CWE-78) reachable through malformed parameters in sensor or notification management. An authenticated attacker with System Administrator web console privileges can execute arbitrary OS commands on the PRTG server and on managed devices. The flaw is remotely reachable over the network and is listed in CISA's Known Exploited Vulnerabilities catalog.

7.2 CVSS 3.1 High CISA KEV since 4 Feb 2025 EPSS 87% · top 0.3% CWE-78 · OS command injection
7.2CVSS 3.1 base score, v2 9.0
87%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
9References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw allows authenticated remote OS command execution with high confidentiality, integrity and availability impact, is in CISA KEV with a very high EPSS score, and public exploits exist, though it requires prior administrative access.

What it is

PRTG Network Monitor before 18.2.39 contains an OS command injection flaw (CWE-78) reachable through malformed parameters in sensor or notification management. An authenticated attacker with System Administrator web console privileges can execute arbitrary OS commands on the PRTG server and on managed devices. The flaw is remotely reachable over the network and is listed in CISA's Known Exploited Vulnerabilities catalog.

Impact

An attacker gains arbitrary OS command execution with the privileges of the PRTG service on the server and on monitored devices. This can lead to full compromise of the monitoring host and lateral movement into monitored infrastructure.

Attack surface

Reached over the network via the PRTG web console (CVSS vector AV:N); the attacker must already hold administrative privileges (PR:H) and no user interaction is required (UI:N). Exploitation occurs through malformed parameters in sensor or notification management requests.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2025-02-04, indicating real-world exploitation, and EPSS gives a 30-day probability of 0.86996 (99.7th percentile). Multiple public exploit references exist, including Exploit-DB 46527 and Packet Storm entries. No ransomware campaign use is documented in the record.

What to do

  • Upgrade PRTG Network Monitor to 18.2.39 or later; this is the primary fix.
  • If immediate patching is not possible, apply the vendor mitigations referenced in the CISA KEV required action or discontinue use of the product.
  • Restrict and audit access to the PRTG System Administrator web console, limiting it to trusted administrators and networks.
  • Place the PRTG web interface behind network segmentation and strong authentication to reduce exposure.
  • Monitor for and review any unexpected changes to sensors, notifications, or device configurations.

Detection

  • Review PRTG web server and application logs for malformed or anomalous parameters in sensor and notification management requests.
  • Monitor for unexpected child processes spawned by the PRTG service (e.g., cmd.exe, /bin/sh) on the PRTG server and monitored devices.
  • Alert on administrative logins to the PRTG console from unusual source IPs or at unusual times.
  • Hunt for outbound connections or command-and-control traffic originating from the PRTG server or managed devices.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-9276 to the Known Exploited Vulnerabilities catalog on 4 February 2025 as "Paessler PRTG Network Monitor OS Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 25 February 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-9276 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-19410PRTG Network Monitor unauthenticated local file inclusion enables admin user creationPRTG Network Monitor before 18.2.40.1683 lets an unauthenticated remote attacker abuse the 'include' directive in /public/login.htm to perform local …KEVEPSS 98%analysed9.8CVE-2020-10374Paessler prtg network monitor improper input validation vulnerabilityA webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST req…EPSS 4.7%8.8CVE-2023-31452Paessler prtg network monitor cross-site request forgery vulnerabilityA cross-site request forgery (CSRF) token bypass was identified in PRTG 23.2.84.1566 and earlier versions that allows remote attackers to perform act…EPSS 0.65%8.8CVE-2018-19411Paessler prtg network monitor improper privilege management vulnerabilityPRTG Network Monitor before 18.2.40.1683 allows an authenticated user with a read-only account to create another user with a read-write account (incl…EPSS 0.87%8.8CVE-2018-19204Paessler prtg network monitor improper input validation vulnerabilityPRTG Network Monitor before 18.3.44.2054 allows a remote authenticated attacker (with read-write privileges) to execute arbitrary code and OS command…EPSS 4.6%7.5CVE-2018-19203Paessler prtg network monitor vulnerabilityPRTG Network Monitor before 18.2.41.1652 allows remote unauthenticated attackers to terminate the PRTG Core Server Service via a special HTTP request.EPSS 2.8%7.5CVE-2018-10253Paessler prtg network monitor memory buffer overflow vulnerabilityPaessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls.EPSS 7.4%7.2CVE-2023-32781Paessler prtg network monitor command injection vulnerabilityA command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an authenticated user with write p…EPSS 14%

Source: NIST National Vulnerability Database (record CVE-2018-9276), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.