Vulnerability record · CVE-2025-28131 · published 1 April 2025
CVE-2025-28131: Nagios network analyzer improper authorization vulnerability
Nagios · Network Analyzer
A Broken Access Control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows low-privilege users with "Read-Only" access to perform administrative actions, including stopping system services and deleting critical resources. This flaw arises due to improper authorization enforcement, enabling unauthorized modifications that compromise system integrity and availability.
Description
A Broken Access Control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows low-privilege users with "Read-Only" access to perform administrative actions, including stopping system services and deleting critical resources. This flaw arises due to improper authorization enforcement, enabling unauthorized modifications that compromise system integrity and availability.
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/harshal79/Privilege-Escalation-in-Nagios-Network-Analyzer.git | Third Party Advisory |
| https://www.nagios.com/changelog/#network-analyzer | Release Notes |
Track CVE-2025-28131 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-28131), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.