CVE-2021-25298
KEV High · CVSS 8.8Nagios XI — OS Command Injection (CWE-78)
- CVSS
- 8.8
- nvd
- EPSS
- 75.2%
- 99th pct
- KEV
- Listed
- 2022-01-18
- Class
- other
- NVD-CWE-Other, CWE-78
Description
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.
Search profile — drives PoC discovery
Symbols cloud-vm.inc.php/usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.phpconfigwizardscloud-vm
Keywords CVE-2021-25298Nagios XI 5.7.5command injectioncloud-vmconfigwizardsnagiosxi RCENagios XI OS command injectionxi-5.7.5
Versions: xi-5.7.5
Ranked PoCs (2) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
- ★ 0k0pak4/k0pak4 needs reviewtrickest
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
- http://packetstormsecurity.com/files/161561/Nagios-XI-5.7.5-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/170924/Nagios-XI-5.7.5-Remote-Code-Execution.html
- https://assets.nagios.com/downloads/nagiosxi/versions.php
- https://github.com/fs0c-sh/nagios-xi-5.7.5-bugs/blob/main/README.md
- https://www.fastly.com/blog/anatomy-of-a-command-injection-cve-2021-25296-7-8-with-metasploit-module-and
- http://packetstormsecurity.com/files/161561/Nagios-XI-5.7.5-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/170924/Nagios-XI-5.7.5-Remote-Code-Execution.html
- https://assets.nagios.com/downloads/nagiosxi/versions.php
- https://github.com/fs0c-sh/nagios-xi-5.7.5-bugs/blob/main/README.md
- https://www.fastly.com/blog/anatomy-of-a-command-injection-cve-2021-25296-7-8-with-metasploit-module-and
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-25298
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z