Summary: A critical security vulnerability (CVE-2025-22604) has been found in the Cacti open-source network monitoring framework, allowing authenticated users to execute arbitrary code remotely. The flaw, which has a high CVSS score of 9.1, affects all versions prior to 1.2.29 and can result in theft, alteration, or deletion of sensitive data. Organizations using Cacti are urged to update to the patched version promptly to mitigate risks.
Affected: Cacti open-source network monitoring framework
Keypoints:
- Vulnerability CVE-2025-22604 allows remote code execution through malformed OIDs by authenticated attackers.
- The flaw affects all versions of Cacti up to and including 1.2.28 and has been fixed in version 1.2.29.
- Another vulnerability, CVE-2025-24367, allows creation of arbitrary PHP scripts, with a CVSS score of 7.2.
- Organizations using Cacti need to apply patches urgently to prevent potential exploits.
Source: https://thehackernews.com/2025/01/critical-cacti-security-flaw-cve-2025.html