Skip to main content

CVE-2021-25298

8.8
HIGHCVSS v3.1 Base Score
75.16%
HIGH RiskEPSS (99th percentile)
KEV
NVD-CWE-Other

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.

Published: 2/15/2021
Modified: 11/3/2025
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

Nagios XI OS Command Injection

Vendor / Product:

Nagios Nagios XI

Required Action:

Apply updates per vendor instructions.

Due Date: 2/1/2022(OVERDUE)
Added to KEV:

1/18/2022

Notes:

https://nvd.nist.gov/vuln/detail/CVE-2021-25298

Vulnerability Summary

CVSS v3 Score

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2 Score

9

AV:N/AC:L/Au:S/C:C/I:C/A:C

EPSS Score (Exploitation Probability)

75.16%HIGH Exploitation Risk
99th percentile

This vulnerability has a 75.16% probability of being exploited in the next 30 days, ranking higher than 99% of all scored CVEs.

CWE Classification

NVD-CWE-Other

Related Vulnerabilities