216.73.217.24

CVE-2025-66399

· Published 02/12/2025 18:15 · Modified 05/12/2025 18:57

Labels: CVE-2025-66399 2025-12-02CVE-2025-66399CWE-77[email protected]

Essential information

Published
02/12/2025 18:15
Modified
05/12/2025 18:57
Author
Creator
CVSS
7.4 HIGH (v3) 7.4 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Cacti is an open source performance and fault management framework. Prior to 1.2.29, there is an input-validation flaw in the SNMP device configuration functionality. An authenticated Cacti user can supply crafted SNMP community strings containing control characters (including newlines) that are accepted, stored verbatim in the database, and later embedded into backend SNMP operations. In environments where downstream SNMP tooling or wrappers interpret newline-separated tokens as command boundaries, this can lead to unintended command execution with the privileges of the Cacti process. This vulnerability is fixed in 1.2.29.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
cacti / cacti cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:*

References