Known exploits

Cacti's PHP codebase has produced a steady stream of high-severity vulnerabilities, and several reach remote code execution on the server. The classes: unauthenticated command injection in the remote-agent/poller handling (reachable where the attacker's address is trusted or the authorization check is bypassed), authenticated command injection through inputs that flow into shell commands (data-source fields, SNMP options passed to the net-snmp binaries, and graph/poller parameters), and SQL-injection chains that extract data or combine with the above. For a target, fingerprint the exact version and match it to the applicable advisory, since the vulnerable endpoint and whether it is pre-authentication are version-specific, some of the most impactful Cacti bugs need no login.

bash
# fingerprint (see enumeration), then match the version to the advisory
curl -sk https://<target>/cacti/CHANGELOG | head -1
# examples of the surfaces (version-specific):
#   unauth command injection via the remote agent handler (poller/remote_agent.php)
#   authenticated command injection via SNMP options / data input reaching net-snmp
#   SQLi chains in graph/management endpoints
# the injected command runs as the Cacti web/poller user on the server.

Exploitation notes#

  • Fingerprint the version and match the advisory: the exploitable endpoint and whether it is unauthenticated are version-specific, and the unauthenticated command-injection flaws are the highest-value (no credentials needed).
  • The authenticated flaws pair with the default/weak login; the SNMP-option injection, for example, needs an authenticated data-source configuration.
  • Execution is as the Cacti web/poller user on the server, which has access to the Cacti database holding every device's stored credentials.
  • Metasploit and public PoCs cover several Cacti chains; the version mapping selects the right one.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more