Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbitrary shell commands via the graph_start GET parameter, which is improperly handled during graph rendering. This flaw allows attackers to execute commands on the underlying operating system with the privileges of the web server process, potentially compromising system integrity.
History

Tue, 02 Sep 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 31 Aug 2025 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Cacti
Cacti cacti
Vendors & Products Cacti
Cacti cacti

Sat, 30 Aug 2025 14:00:00 +0000

Type Values Removed Values Added
Description Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbitrary shell commands via the graph_start GET parameter, which is improperly handled during graph rendering. This flaw allows attackers to execute commands on the underlying operating system with the privileges of the web server process, potentially compromising system integrity.
Title Cacti graph_view.php RCE via graph_start Parameter Injection
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-08-30T13:45:16.222Z

Updated: 2025-09-02T20:44:10.062Z

Reserved: 2025-08-28T18:08:00.944Z

Link: CVE-2005-10004

cve-icon Vulnrichment

Updated: 2025-09-02T20:44:05.677Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-30T14:15:32.040

Modified: 2025-09-02T15:55:25.420

Link: CVE-2005-10004

cve-icon Redhat

No data.