Known server exploits

Separate from abusing Zabbix's intended command features, the Zabbix server and frontend have carried genuine vulnerabilities reaching remote code execution. The classes span the PHP frontend (injection and deserialization-style flaws, and the SQLi-to-RCE chains), the server's trapper protocol on 10051 (which parses data from agents, proxies, and senders), and authentication/session handling that chains to execution. Some are pre-authentication. For an attacker these are the route when the scripting features are not reachable (no admin, restricted role) or when a direct unauthenticated exploit is simpler. The method is to fingerprint the exact Zabbix build and match it to the applicable advisory, since the vulnerable component and request differ by version.

bash
# fingerprint (unauthenticated), then match to the advisory
curl -sk https://<target>/zabbix/api_jsonrpc.php -H 'Content-Type: application/json-rpc' \
  -d '{"jsonrpc":"2.0","method":"apiinfo.version","params":{},"id":1}'
nmap -p10051 -sV <target>                        # trapper (server protocol) reachable?
# the exploit is version-specific: frontend RCE, SQLi-to-RCE chain, or trapper-side bug.

Exploitation notes#

  • The version is decisive: apiinfo.version is unauthenticated and maps to the applicable frontend or trapper RCE; there is no universal exploit, so fingerprint and match.
  • The trapper port (10051) is a distinct, often-overlooked surface: it parses data from agents/proxies/senders and has had parsing vulnerabilities; check whether it is reachable.
  • Pre-authentication exploits are the cleanest where available; post-auth ones pair with the authentication routes.
  • Where no server bug applies, the feature-based scripts, items, and agent paths remain the reliable RCE for an authenticated attacker.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more