Known exploits

PRTG's best-known vulnerability is the authenticated command injection through the notification parameter, which runs as SYSTEM and is covered as Notification command abuse; it is the most impactful and reliable path and is the one to reach for once authenticated. Beyond it, PRTG has had other web-interface and authentication issues over its releases. For a target, fingerprint the PRTG version and match it to the applicable advisory to confirm which issues are present and whether the notification injection is patched. Where the notification path is fixed, the remaining issues are version-specific and generally lower impact, so the version mapping decides the approach.

bash
# fingerprint, then match to the advisory
curl -sk https://<target>/index.htm | grep -ioE 'PRTG[^<]*Version [0-9.]+'
# the notification-parameter command injection (SYSTEM) is the primary chain where unpatched;
# Metasploit includes a PRTG authenticated RCE module targeting it.

Exploitation notes#

  • The notification-parameter injection to SYSTEM is the headline and the most useful; confirm from the version whether it is patched, and if not, use the notification abuse path.
  • Other PRTG issues are version-specific and mostly lower impact; map the version to advisories to enumerate them.
  • All of this assumes reaching the web interface; default/weak credentials are usually the access step, so the full chain is often default-login then notification RCE.
  • Metasploit packages the authenticated RCE; the manual create-and-trigger is on the notification page.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more