CVE-2025-22604: Cacti has Authenticated RCE via multi-line SNMP responses
Cacti is an open source performance and fault management framework. Due to a flaw in multi-line SNMP result parser, authenticated users can inject malformed OIDs in the response. When processed by ssnetsnmpdiskio() or ssnetsnmpdiskbytes(), a part of each OID will be used as a key in an array that is used as part of a system command, causing a command execution vulnerability. This vulnerability is fixed in 1.2.29.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22604?
The severity level of CVE-2025-22604 is considered to be high due to its potential for exploitation by authenticated users.
How do I fix CVE-2025-22604?
To fix CVE-2025-22604, upgrade Cacti to version 1.2.30 or later where the vulnerability has been addressed.
Who is affected by CVE-2025-22604?
CVE-2025-22604 affects all versions of Cacti up to and including 1.2.29.
What types of attacks can CVE-2025-22604 enable?
CVE-2025-22604 can enable crafted OID injections by authenticated users, potentially leading to data manipulation or service disruption.
Is authentication required to exploit CVE-2025-22604?
Yes, authentication is required to exploit CVE-2025-22604, as the vulnerability affects authenticated users only.