CVE-2018-9276 is an OS command injection vulnerability in PRTG Network Monitor versions prior to 18.2.39. The vulnerability exists in the web console, specifically in sensor or notification management scenarios, where an authenticated attacker with administrative privileges can send malformed parameters to inject arbitrary operating system commands. This affects both the server and managed devices.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a single Python exploit script, a README, and a requirements file. The exploit targets CVE-2018-9276 in Paessler PRTG Network Monitor before 18.2.39, an authenticated command injection in the notifications feature, specifically through the built-in PowerShell demo notification script. The script is a standalone operational exploit rather than a framework module. Primary workflow: it parses target and callback parameters, checks the target version, authenticates with PRTG using supplied or default credentials, stages a writable output file on the Windows target, generates a malicious DLL reverse shell with msfvenom, optionally starts an SMB server using impacket to host that DLL, injects a command using rundll32.exe against a UNC path, triggers the vulnerable notification test path, and finally starts a netcat listener to receive the reverse shell. The intended result is code execution as Local System. Notable capabilities include authenticated exploitation over HTTP or HTTPS, acceptance of self-signed certificates, optional use of an externally hosted payload via --no-smb and --shell-location, randomized payload/share naming, and local listener orchestration. The exploit depends on external tooling: msfvenom for payload generation, nc for shell handling, and optionally impacket/colorama. Repository structure is minimal and purpose-built: README.md documents the vulnerability, exploitation logic, usage examples, and mitigations; cve_2018_9276.py implements the exploit logic; requirements.txt lists Python dependencies. Based on the available code and documentation, this is a real exploit PoC with an embedded payload-delivery chain, not merely a detector.
Repository contains a single Python exploit script, a README, and a requirements file. The exploit targets CVE-2018-9276 in Paessler PRTG Network Monitor before 18.2.39. It is a real authenticated RCE exploit, not just a detector. The script automates the full attack chain: checking the target version, authenticating to the PRTG web interface, creating or staging notification actions, initializing a writable output file on the Windows target, generating a malicious DLL reverse shell with msfvenom, optionally starting an SMB server using impacket to host that DLL, injecting a command into the vulnerable PowerShell-based notification parameter, triggering execution through PRTG's notification test functionality, and finally launching a netcat listener to receive the callback shell. The exploit's core capability is authenticated command injection leading to code execution as Local System. Its operational payload is a reverse shell delivered as a DLL and executed with rundll32.exe from a UNC path. This makes the exploit more than a bare PoC: it includes payload generation, hosting, delivery, and listener orchestration, but payload behavior is still fairly fixed and basic, so OPERATIONAL is the best maturity fit. Repository structure is minimal: README.md documents the vulnerability, exploitation flow, prerequisites, and usage examples; requirements.txt lists impacket and colorama; cve_2018_9276.py is the main executable. The script uses Python standard libraries plus optional colorama for terminal output and impacket for SMB hosting. It accepts target host/port, credentials, callback host/port, HTTPS mode, and options to skip the built-in SMB server or override the DLL UNC path. Fingerprintable observables include the target-side staging file C:\Users\Public\tester.txt, attacker-side /tmp storage for the generated DLL, the UNC DLL path \\<attacker>\<share>\<payload>.dll, and the documented PRTG trigger endpoint /api/notificationtest.htm. The exploit also relies on external tools msfvenom and nc. Overall, this repository is a compact end-to-end exploit for authenticated web-to-system compromise of vulnerable Windows-hosted PRTG instances.
This repository is a small standalone authenticated RCE exploit for CVE-2018-9276 affecting Paessler PRTG Network Monitor. It contains one Python exploit script and one README with usage notes and a demonstration transcript. The Python code uses the requests library and implements a simple exploitation workflow inside a PRTGExploit class: authenticate to the PRTG web interface, create a malicious notification object, inject an attacker-controlled command into the EXE/script notification field message_10 using a semicolon command separator, trigger the notification test endpoint to execute the payload, and finally delete the created notification object for cleanup. The exploit is not a scanner or detector; it performs real authenticated exploitation. The included example payload is a base64-encoded PowerShell reverse shell callback, and the README shows a successful shell as NT AUTHORITY\SYSTEM. Repository structure is minimal: CVE-2018-9276.py is the operational entry point, while README.md explains manual configuration of target URL, username, password, and payload command.
This repository contains a single Metasploit module (Ruby file) that exploits an authenticated remote code execution (RCE) vulnerability (CVE-2018-9276) in Paessler PRTG Network Monitor versions prior to 18.2.39. The exploit requires valid credentials for the PRTG web interface. It works by logging in, creating a malicious notification that executes a user-supplied Powershell payload, triggering the notification, and then cleaning up by deleting it. The module leverages Metasploit's Powershell payload generation to deliver arbitrary commands or a reverse shell to the target Windows system. The attack is performed over HTTP(S) endpoints exposed by the PRTG web interface. The code is operational and suitable for real-world exploitation, provided the attacker has valid credentials and network access to the PRTG server.
This repository contains a Python exploit script (CVE-2018-9276.py) and a README.md for CVE-2018-9276, targeting PRTG Network Monitor versions prior to 18.2.39 on Windows. The exploit requires valid administrator credentials (default: prtgadmin/prtgadmin) and leverages authenticated command injection to achieve remote code execution. The script checks the target's version, authenticates to the web interface, and sets up an SMB server using Impacket to serve a DLL payload generated by msfvenom. The target is coerced into loading this DLL via rundll32.exe, resulting in a reverse shell to the attacker's specified LHOST:LPORT. The exploit assumes outbound SMB access is allowed from the target. The repository is operational, providing a working exploit with a customizable payload, and is not part of a larger framework. The README provides usage instructions, dependencies, and configuration assumptions.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.