vendor:
PRTG Network Monitor
by:
https://github.com/M4LV0
7.2
CVSS
HIGH
Remote Code Execution
20
CWE
Product Name: PRTG Network Monitor
Affected Version From: Not specified
Affected Version To: 18.2.38
Patch Exists: YES
Related CWE: CVE-2018-9276
CPE: a:paessler:prtg_network_monitor:18.2.38
Platforms Tested:
2019
Authenticated PRTG network Monitor remote code execution
This script is used to create a new user 'pentest' in the administrators group with the password 'P3nT3st!' in the PRTG Network Monitor application. The exploit requires authentication and the script uses a cookie for authentication. Default credentials for the application are prtgadmin/prtgadmin.
Mitigation:
Apply the latest patch or update to version 18.2.38 or later. Change default credentials for the application.