Cyber Resilience

CVE-2018-19410

Paessler Prtg Network Monitor ≤ 18.2.40.1683

CISA KEVActive ExploitationEUVD Exploited
Published
21 November 2018
Modified
07 November 2025
KEV Added
04 February 2025
CVSS Score v3.1 9.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.87 99.7th percentile
Risk Priority 97 floored blend · peak EPSS

Summary

CVE-2018-19410 is a critical-severity an unspecified weakness vulnerability in Paessler Prtg Network Monitor. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 0.3% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

PRTG Network Monitor versions prior to 18.2.40.1683 contain a vulnerability that permits remote unauthenticated attackers to create users possessing read-write privileges, including full administrator accounts. The flaw stems from improper handling of the include directive within the /public/login.htm page, which can be manipulated to perform local file inclusion of the /api/addusers endpoint.

An attacker can exploit the issue by sending a crafted HTTP request that overrides the include directive and supplies the id and users parameters to the API endpoint, resulting in immediate creation of a privileged account. No authentication or user interaction is required, and the attack can be carried out over the network with minimal complexity.

Public references from Positive Technologies detail the technical root cause and confirm the affected versions, while CISA lists the CVE in its catalog of known exploited vulnerabilities, underscoring the need to apply the vendor patch that introduced the fixed release.

EU & UK References

Vulnerability Data

PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user can craft an HTTP request and override attributes of the 'include' directive in /public/login.htm and perform a Local File…

more

Inclusion attack, by including /api/addusers and executing it. By providing the 'id' and 'users' parameters, an unauthenticated attacker can create a user with read-write privileges (including administrator).

CWE(s)
KEV Date Added
04 February 2025

Related Threats

CVEs Like This One

CVE-2018-9276Same product: Paessler Prtg Network Monitorboth on KEV
CVE-2025-67834Same product: Paessler Prtg Network Monitor
CVE-2023-31448Same product: Paessler Prtg Network Monitor
CVE-2025-67833Same product: Paessler Prtg Network Monitor
CVE-2023-31449Same product: Paessler Prtg Network Monitor
CVE-2025-67835Same product: Paessler Prtg Network Monitor
CVE-2023-51630Same product: Paessler Prtg Network Monitor
CVE-2023-32782Same product: Paessler Prtg Network Monitor
CVE-2023-31450Same product: Paessler Prtg Network Monitor
CVE-2023-32781Same product: Paessler Prtg Network Monitor

Affected Assets

paessler
prtg network monitor
≤ 18.2.40.1683

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References