Unrated severityNVD Advisory· Published Oct 30, 2025· Updated Nov 17, 2025
Nagios XI < 5.4.13 Component Download Page RCE
CVE-2018-25122
Description
Nagios XI versions prior to 5.4.13 contain a remote code execution vulnerability in the Component Download page. The download/import handler used unsafe command construction with attacker-controlled input and lacked sufficient validation and output encoding, allowing an authenticated user to inject commands or otherwise execute arbitrary code with the privileges of the application service.
Affected products
2- Nagios/XIv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.nagios.com/changelog/nagios-xi/mitrerelease-notespatch
- www.vulncheck.com/advisories/nagios-xi-component-download-page-rcemitrethird-party-advisory
News mentions
0No linked articles in our index yet.