Separate from abusing Zabbix's intended command features, the Zabbix server and frontend have carried genuine vulnerabilities reaching remote code execution. The classes span the PHP frontend (injection and deserialization-style flaws, and the SQLi-to-RCE chains), the server's trapper protocol on 10051 (which parses data from agents, proxies, and senders), and authentication/session handling that chains to execution. Some are pre-authentication. For an attacker these are the route when the scripting features are not reachable (no admin, restricted role) or when a direct unauthenticated exploit is simpler. The method is to fingerprint the exact Zabbix build and match it to the applicable advisory, since the vulnerable component and request differ by version.
# fingerprint (unauthenticated), then match to the advisory
curl -sk https://<target>/zabbix/api_jsonrpc.php -H 'Content-Type: application/json-rpc' \
-d '{"jsonrpc":"2.0","method":"apiinfo.version","params":{},"id":1}'
nmap -p10051 -sV <target> # trapper (server protocol) reachable?
# the exploit is version-specific: frontend RCE, SQLi-to-RCE chain, or trapper-side bug.
Exploitation notes#
- The version is decisive:
apiinfo.versionis unauthenticated and maps to the applicable frontend or trapper RCE; there is no universal exploit, so fingerprint and match. - The trapper port (10051) is a distinct, often-overlooked surface: it parses data from agents/proxies/senders and has had parsing vulnerabilities; check whether it is reachable.
- Pre-authentication exploits are the cleanest where available; post-auth ones pair with the authentication routes.
- Where no server bug applies, the feature-based scripts, items, and agent paths remain the reliable RCE for an authenticated attacker.