Vulnerability record · CVE-2021-25296 · published 15 February 2021
CVE-2021-25296: Nagios XI Windows WMI Config Wizard OS Command Injection
Nagios · Nagios Xi
Nagios XI 5.7.5 fails to sanitize authenticated user input in the windowswmi config wizard file, allowing OS command injection. Because the affected component runs on the Nagios XI server, successful exploitation gives command execution in the context of the web server.
Description
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is in CISA KEV with public exploit code and a very high EPSS score, and it yields remote command execution on a monitoring server.
What it is
Nagios XI 5.7.5 fails to sanitize authenticated user input in the windowswmi config wizard file, allowing OS command injection. Because the affected component runs on the Nagios XI server, successful exploitation gives command execution in the context of the web server.
Impact
An authenticated attacker can execute arbitrary operating system commands on the Nagios XI server, leading to full compromise of the monitoring host and any credentials or data it holds.
Attack surface
Reachable over the network through a single HTTP request to the windowswmi config wizard; the CVSS vector requires low privileges (PR:L) and no user interaction (UI:N).
Exploitation
CVE-2021-25296 is listed in CISA KEV with a 2022-01-18 addition date, and public exploit references plus a Metasploit module exist; EPSS 30-day probability is 0.72182 (99.4th percentile).
What to do
- Upgrade Nagios XI to a version later than 5.7.5 per the vendor versions page.
- Restrict access to the Nagios XI web interface to trusted administrative networks.
- Review and remove unnecessary accounts with access to config wizards.
- Monitor for unexpected child processes spawned by the Nagios XI web server.
Detection
- Alert on HTTP requests to /nagiosxi/includes/configwizards/windowswmi/windowswmi.inc.php with shell metacharacters in parameters.
- Hunt for command shells or unusual binaries spawned by the Nagios XI web server user.
- Correlate Nagios XI web logs with process creation events on the host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-25296 to the Known Exploited Vulnerabilities catalog on 18 January 2022 as "Nagios XI OS Command Injection". Required action: Apply updates per vendor instructions. Federal deadline 1 February 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-25296 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-25296), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.