Cacti's PHP codebase has produced a steady stream of high-severity vulnerabilities, and several reach remote code execution on the server. The classes: unauthenticated command injection in the remote-agent/poller handling (reachable where the attacker's address is trusted or the authorization check is bypassed), authenticated command injection through inputs that flow into shell commands (data-source fields, SNMP options passed to the net-snmp binaries, and graph/poller parameters), and SQL-injection chains that extract data or combine with the above. For a target, fingerprint the exact version and match it to the applicable advisory, since the vulnerable endpoint and whether it is pre-authentication are version-specific, some of the most impactful Cacti bugs need no login.
# fingerprint (see enumeration), then match the version to the advisory
curl -sk https://<target>/cacti/CHANGELOG | head -1
# examples of the surfaces (version-specific):
# unauth command injection via the remote agent handler (poller/remote_agent.php)
# authenticated command injection via SNMP options / data input reaching net-snmp
# SQLi chains in graph/management endpoints
# the injected command runs as the Cacti web/poller user on the server.
Exploitation notes#
- Fingerprint the version and match the advisory: the exploitable endpoint and whether it is unauthenticated are version-specific, and the unauthenticated command-injection flaws are the highest-value (no credentials needed).
- The authenticated flaws pair with the default/weak login; the SNMP-option injection, for example, needs an authenticated data-source configuration.
- Execution is as the Cacti web/poller user on the server, which has access to the Cacti database holding every device's stored credentials.
- Metasploit and public PoCs cover several Cacti chains; the version mapping selects the right one.