LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-19410: Paessler PRTG Network Monitor Local File Inclusion Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 4, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Feb 25, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-19410 to its Known Exploited Vulnerabilities catalog on Feb 4, 2025, with a federal patch deadline of Feb 25, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote, unauthenticated attacker to create users with read-write privileges (including administrator).

CVE-2018-19410 is a local file inclusion vulnerability in Paessler PRTG Network Monitor. It allows a remote, unauthenticated attacker to create users with read-write privileges, including administrator accounts. This matters because successful abuse can give an outsider full control of the monitoring platform, which often holds network credentials, device inventories, and configuration data that can be leveraged for further compromise.

Defenders should treat any exposed or internet-facing PRTG instance as high priority until the issue is confirmed remediated against the vendor advisory.

How it works

The flaw is described as a local file inclusion vulnerability. In this class of weakness, an attacker can cause the application to process or include a file from the local filesystem in a way the developers did not intend. According to the CISA summary, the practical outcome in PRTG Network Monitor is that a remote attacker who has not authenticated can create new user accounts that possess read-write rights, up to and including administrator-level privileges.

Exact request paths, parameters, or file targets are not provided in the available facts; those details must be confirmed against the vendor advisory. Once an attacker-controlled account exists, the adversary can log in, alter monitoring configurations, harvest stored credentials, or use the platform as a foothold inside the network.

Am I affected? How to find it in your systems

PRTG Network Monitor is typically deployed on Windows servers (or virtual machines) that collect metrics from network devices, servers, and applications. It is commonly found in network operations centers, managed-service-provider environments, and enterprise monitoring stacks.

How to remediate

Apply the vendor-supplied update that addresses CVE-2018-19410 as the primary remediation. Follow the installation and verification steps published by Paessler; the CISA required action is to apply mitigations per vendor instructions or to discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be applied, reduce the attack surface with compensating controls.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to unauthorized access and data exposure. Review PRTG logs and any downstream systems for signs of compromise, rotate credentials that may have been stored or retrieved through the platform, and consider running a free exposure scan of organizational email addresses against known breach data sets to determine whether related accounts appear in public breach collections.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedPaessler · PRTG Network Monitor
Added to CISA KEVFeb 4, 2025
Federal patch deadlineFeb 25, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities