Cyber Resilience

CVE-2021-25296

Nagios Xi 5.5.6 – 5.7.5

CISA KEVActive ExploitationEUVD ExploitedPublic PoC
Published
15 February 2021
Modified
09 July 2026
KEV Added
18 January 2022
Patch / advisory
CVSS Score v3.1 8.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.72 99.4th percentile
Risk Priority 90 floored blend · peak EPSS

Summary

CVE-2021-25296 is a high-severity an unspecified weakness vulnerability in Nagios Nagios Xi. Its CVSS base score is 8.8 (High).

Operationally, ranked in the top 0.6% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog; a public proof-of-concept is referenced.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

Nagios XI version xi-5.7.5 is affected by an OS command injection vulnerability in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php. The flaw arises from improper sanitization of input supplied by authenticated users in a single HTTP request, allowing arbitrary operating system commands to be executed on the Nagios XI server.

Authenticated attackers with network access can exploit the issue without user interaction to achieve remote code execution, resulting in complete loss of confidentiality, integrity, and availability on the affected server.

Public proof-of-concept code for remote code execution against this version has been released on PacketStorm Security, and additional technical details are hosted in a GitHub repository documenting Nagios XI bugs. Nagios references its versions page and main site for obtaining updated releases.

EU & UK References

Vulnerability Data

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios…

more

XI server.

CWE(s)
KEV Date Added
18 January 2022

Related Threats

CVEs Like This One

CVE-2021-25297Same product: Nagios Nagios Xiboth on KEV
CVE-2021-25298Same product: Nagios Nagios Xiboth on KEV
CVE-2019-15949Same product: Nagios Nagios Xiboth on KEV
CVE-2024-14003Same product: Nagios Nagios Xi
CVE-2025-56432Same product: Nagios Nagios Xi
CVE-2023-53688Same product: Nagios Nagios Xi
CVE-2023-7314Same product: Nagios Nagios Xi
CVE-2024-14005Same product: Nagios Nagios Xi
CVE-2024-14000Same product: Nagios Nagios Xi
CVE-2025-34134Same product: Nagios Nagios Xi

Affected Assets

nagios
nagios xi
5.5.6 — 5.7.5

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References