CVE-2018-19410 is a critical vulnerability affecting PRTG Network Monitor before version 18.2.40.1683. It allows remote, unauthenticated attackers to create users with full read-write privileges, including administrator access, through a Local File Inclusion attack leveraging a crafted HTTP request to override attributes in /public/login.htm. This vulnerability carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, listed in CISA's KEV catalog, and has significant community discussion and media coverage, with Nuclei templates available for detection.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.2.40.1683CPE matchmatch criteria | cpe:2.3:a:paessler:prtg_network_monitor:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.