← Vulnerability feed

Vulnerability record · CVE-2020-11547 · published 5 April 2020

CVE-2020-11547: PRTG Network Monitor unauthenticated information disclosure via HTTP request

Paessler · Prtg Network Monitor

PRTG Network Monitor before 20.1.57.1745 exposes server and probe details to unauthenticated remote users through HTTP requests such as type=probes to login.htm or index.htm. The flaw is a missing authentication check (CWE-306) on a function that returns CPU usage, memory, Windows version and internal statistics. It matters because reconnaissance data is available without credentials, easing follow-on targeting of the monitoring infrastructure.

5.3 CVSS 3.1 Medium EPSS 52% · top 1.1% CWE-306 · Missing authentication for critical function
5.3CVSS 3.1 base score, v2 5.0
52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version, and internal statistics) via an HTTP request, as demonstrated by type=probes to login.htm or index.htm.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

medium priorityThe flaw is remotely exploitable without authentication but only discloses information, with no confirmed public exploit or KEV listing.

What it is

PRTG Network Monitor before 20.1.57.1745 exposes server and probe details to unauthenticated remote users through HTTP requests such as type=probes to login.htm or index.htm. The flaw is a missing authentication check (CWE-306) on a function that returns CPU usage, memory, Windows version and internal statistics. It matters because reconnaissance data is available without credentials, easing follow-on targeting of the monitoring infrastructure.

Impact

An attacker gains internal operational details about the PRTG server and its probes, including resource usage, OS version and statistics. This is information disclosure only; the CVSS vector shows no integrity or availability impact.

Attack surface

Reachable over the network via HTTP requests to login.htm or index.htm with parameters such as type=probes. No authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Not listed in CISA KEV and no ransomware association is recorded. EPSS is high (0.52059, 98.9th percentile), but the only references are marked Broken Link, so no public exploit code is confirmed by this record.

What to do

  • Upgrade PRTG Network Monitor to version 20.1.57.1745 or later.
  • Restrict network access to the PRTG web interface to trusted management networks.
  • Place the PRTG interface behind authentication-aware reverse proxy or VPN where feasible.
  • Monitor for unauthenticated requests using parameters such as type=probes against login.htm and index.htm.

Detection

  • Search web logs for requests to login.htm or index.htm containing type=probes from unauthenticated sources.
  • Alert on access to PRTG management endpoints from IPs outside expected administrative ranges.
  • Baseline normal PRTG web request patterns and flag anomalous parameter usage.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-11547 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-19410PRTG Network Monitor unauthenticated local file inclusion enables admin user creationPRTG Network Monitor before 18.2.40.1683 lets an unauthenticated remote attacker abuse the 'include' directive in /public/login.htm to perform local …KEVEPSS 98%analysed7.2CVE-2018-9276PRTG Network Monitor OS Command Injection via Malformed ParametersPRTG Network Monitor before 18.2.39 contains an OS command injection flaw (CWE-78) reachable through malformed parameters in sensor or notification m…KEVEPSS 87%analysed9.8CVE-2020-10374Paessler prtg network monitor improper input validation vulnerabilityA webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST req…EPSS 4.7%8.8CVE-2023-31452Paessler prtg network monitor cross-site request forgery vulnerabilityA cross-site request forgery (CSRF) token bypass was identified in PRTG 23.2.84.1566 and earlier versions that allows remote attackers to perform act…EPSS 0.65%8.8CVE-2018-19411Paessler prtg network monitor improper privilege management vulnerabilityPRTG Network Monitor before 18.2.40.1683 allows an authenticated user with a read-only account to create another user with a read-write account (incl…EPSS 0.87%8.8CVE-2018-19204Paessler prtg network monitor improper input validation vulnerabilityPRTG Network Monitor before 18.3.44.2054 allows a remote authenticated attacker (with read-write privileges) to execute arbitrary code and OS command…EPSS 4.6%7.5CVE-2018-19203Paessler prtg network monitor vulnerabilityPRTG Network Monitor before 18.2.41.1652 allows remote unauthenticated attackers to terminate the PRTG Core Server Service via a special HTTP request.EPSS 2.8%7.5CVE-2018-10253Paessler prtg network monitor memory buffer overflow vulnerabilityPaessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls.EPSS 7.4%

Source: NIST National Vulnerability Database (record CVE-2020-11547), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.