Cacti's default administrator is admin with the password admin. Newer versions prompt to change it on first login, but installations that were upgraded, scripted, or simply ignored frequently retain admin/admin or a weak replacement, and Cacti has historically applied no strong password policy. A web login as admin grants access to the data-source and device configuration, where the SNMP strings and credentials Cacti uses to poll are stored, and to the authenticated command-injection and configuration features that several of its vulnerabilities exploit. So default or weak credentials are the common access step before credential harvesting or an authenticated RCE chain.
# default admin login (form posts to index.php with a CSRF token)
curl -sk -c cj https://<target>/cacti/index.php | grep -oE 'csrfMagicToken="[^"]+"' # grab token
curl -sk -b cj -c cj https://<target>/cacti/index.php \
--data 'action=login&login_username=admin&login_password=admin&__csrf_magic=<token>'
Exploitation notes#
- Try
admin/adminfirst; despite the first-login prompt, it persists on many instances, and weak replacements are common. - Cacti's login uses a CSRF token (
__csrf_magic) that must be fetched and submitted; scripted logins grab it from the login page first. - Admin access unlocks credential harvesting (the stored SNMP/device credentials) and the authenticated portions of the exploit chains; some Cacti RCE is unauthenticated and needs no login.
- Weak/reused passwords and no lockout on older versions make spraying viable.