CVE-2018-9276
Summary
| CVE | CVE-2018-9276 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-02 16:29:00 UTC |
| Updated | 2023-04-25 15:41:00 UTC |
| Description | An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios. |
Risk And Classification
EPSS: 0.871730000 probability, percentile 0.997340000 (date 2026-07-22)
CISA KEV: Listed on 2025-02-04; due 2025-02-25; ransomware use Unknown
Problem Types: CWE-78
CISA Known Exploited Vulnerability
| Vendor | Paessler |
|---|---|
| Product | PRTG Network Monitor |
| Name | Paessler PRTG Network Monitor OS Command Injection Vulnerability |
| Required Action | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
| Notes | https://www.paessler.com/prtg/history/prtg-18#18.2.39 ; https://nvd.nist.gov/vuln/detail/CVE-2018-9276 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Paessler | Prtg Network Monitor | All | All | All | All |
| Application | Paessler Ag | Prtg Network Monitor | All | All | All | All |
| Application | Paessler Ag | Prtg Network Monitor | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PRTG Network Monitor 18.2.38 - (Authenticated) Remote Code Execution - Windows webapps Exploit | EXPLOIT-DB | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | Third Party Advisory, VDB Entry |
| PRTG Network Monitor Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| PRTG Command Injection ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Mitigation, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.