Fusion
Vendor:
First CVE: Jun 16, 2018 · Active for 8 years
19
Total CVEs
More Total CVEs than 95% of tracked products
6.3
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 65% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Fusion over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 16, 2018
8 years ago
Most Recent CVE
Oct 30, 2025
270 days ago
CVE Severity & Scoring
Fusion19 CVEs
42%
26%
32%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (94.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (5.3%)
Attack Complexity
Low19 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None12 (63.2%)
Unknown0 (0.0%)
Required7 (36.8%)
Privileges Required
Low5 (26.3%)
High3 (15.8%)
None11 (57.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-28905HIGH Improper Input Validation in Nagios Fusion 4.1.8 and earlier allows an authenticated attacker to execute remote code via table pagination. | May 24, 2021 | 8.8 | 39 | NO | NO |
CVE-2020-28901CRITICAL Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vectors related to corrupt component installation in cmd_subsys.p | May 24, 2021 | 9.8 | 33 | NO | NO |
CVE-2020-28902CRITICAL Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php. | May 24, 2021 | 9.8 | 32 | NO | NO |
CVE-2020-28908CRITICAL Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to nagios. | May 24, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-28904CRITICAL Execution with Unnecessary Privileges in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation as nagios via installation of a malicious component containing PHP code. | May 24, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-28900CRITICAL Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via | May 24, 2021 | 9.8 | 28 | NO | NO |
CVE-2025-60425HIGH Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabled, allowing attackers to perform a ses | Oct 27, 2025 | 8.6 | 27 | NO | NO |
CVE-2020-28909HIGH Incorrect File Permissions in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root via modification of scripts. Low-privileges users are able to modify files tha | May 24, 2021 | 8.8 | 27 | NO | NO |
CVE-2020-28906HIGH Incorrect File Permissions in Nagios XI 5.7.5 and earlier and Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root. Low-privileged users are able to modify files | May 24, 2021 | 8.8 | 27 | NO | NO |
CVE-2025-60424HIGH A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication via a bruteforce attack. | Oct 27, 2025 | 7.6 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For Fusion
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.0.0 | 1 | 6.1 | 0.5% | 0 | 0 |
| 2024 | 2 | 8.1 | 0.8% | 0 | 0 |