AUGUST 5, 2026
Live Feed
Back to database
Case File

CVE-2018-19204

HIGH · CVSS 8.8 EPSS 4.64%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-11-12 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.8. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.

CVE
CVE-2018-19204
Severity
HIGH
CVSS
8.8
EPSS
4.64%

Original NVD Description

PRTG Network Monitor before 18.3.44.2054 allows a remote authenticated attacker (with read-write privileges) to execute arbitrary code and OS commands with system privileges. When creating an HTTP Advanced Sensor, the user's input in the POST parameter 'proxyport_' is mishandled. The attacker can craft an HTTP request and override the 'writeresult' command-line parameter for HttpAdvancedSensor.exe to store arbitrary data in an arbitrary place on the file system. For example, the attacker can create an executable file in the \Custom Sensors\EXE directory and execute it by creating EXE/Script Sensor.

Related CVEs

Other vulnerabilities affecting the same vendor(s)