Skip to main content

CVE-2021-25296

8.8
HIGHCVSS v3.1 Base Score
93.29%
HIGH RiskEPSS (100th percentile)
KEV
NVD-CWE-Other

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.

Published: 2/15/2021
Modified: 11/3/2025
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

Nagios XI OS Command Injection

Vendor / Product:

Nagios Nagios XI

Required Action:

Apply updates per vendor instructions.

Due Date: 2/1/2022(OVERDUE)
Added to KEV:

1/18/2022

Notes:

https://nvd.nist.gov/vuln/detail/CVE-2021-25296

Vulnerability Summary

CVSS v3 Score

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2 Score

9

AV:N/AC:L/Au:S/C:C/I:C/A:C

EPSS Score (Exploitation Probability)

93.29%HIGH Exploitation Risk
100th percentile

This vulnerability has a 93.29% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.

CWE Classification

NVD-CWE-Other

Related Vulnerabilities