Vulnerability record · CVE-2021-25299 · published 15 February 2021
CVE-2021-25299: Nagios XI sshterm.php reflected XSS enabling admin session theft
Nagios · Nagios Xi
Nagios XI 5.7.5 fails to sanitize user-controlled input in /usr/local/nagiosxi/html/admin/sshterm.php, allowing reflected cross-site scripting. A crafted URL clicked by an authenticated admin can leak session cookies or be chained into one-click remote command execution on the Nagios XI server.
Description
Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to steal his/her session cookies or it can be chained with the previous bugs to get one-click remote command execution (RCE) on the Nagios XI server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityThe flaw requires admin interaction but has public exploit code and an extremely high EPSS score, with a path to full RCE on a monitoring server.
What it is
Nagios XI 5.7.5 fails to sanitize user-controlled input in /usr/local/nagiosxi/html/admin/sshterm.php, allowing reflected cross-site scripting. A crafted URL clicked by an authenticated admin can leak session cookies or be chained into one-click remote command execution on the Nagios XI server.
Impact
An attacker who lures an admin into clicking a crafted link can steal that admin's session cookies and hijack the session, or chain the flaw to achieve remote command execution on the Nagios XI host.
Attack surface
Reached over the network via a crafted URL to the sshterm.php admin page; the victim must be an authenticated admin and must click the link, so user interaction is required and no prior authentication is needed by the attacker.
Exploitation
Public exploit code is referenced (PacketStorm and a GitHub PoC), and EPSS is very high at 0.9776 (99.9th percentile), though the CVE is not listed in CISA KEV.
What to do
- Upgrade Nagios XI past 5.7.5 to a fixed release; verify against the vendor versions page.
- Restrict admin interface access to trusted networks or VPN and avoid exposing Nagios XI directly to the internet.
- Set session cookies HttpOnly and Secure, and enforce short session lifetimes to limit cookie theft impact.
- Train admins not to click unsolicited links to Nagios XI admin pages and enforce phishing-resistant MFA where supported.
Detection
- Review web logs for requests to /nagiosxi/html/admin/sshterm.php containing script or encoded payloads in parameters.
- Alert on admin session cookie reuse from unexpected source IPs or user agents.
- Monitor for unexpected child processes or command execution spawned by the Nagios XI web server user.
- Hunt for outbound connections from the Nagios XI host following admin page access.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/161561/Nagios-XI-5.7.5-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://assets.nagios.com/downloads/nagiosxi/versions.php | Product |
| https://github.com/fs0c-sh/nagios-xi-5.7.5-bugs/blob/main/README.md | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/161561/Nagios-XI-5.7.5-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://assets.nagios.com/downloads/nagiosxi/versions.php | Product |
| https://github.com/fs0c-sh/nagios-xi-5.7.5-bugs/blob/main/README.md | ExploitThird Party Advisory |
Track CVE-2021-25299 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-25299), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.