Command injection in Cacti - CVE-2025-66399

 

Command injection in Cacti - CVE-2025-66399

Published: December 2, 2025


Vulnerability identifier: #VU118996
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-66399
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary commands on the system.

The vulnerability exists due to insufficient input validation whenhandling newline characters. A remote user can supply crafted SNMP community strings containing control characters that are accepted, stored verbatim in the database, and later embedded into backend SNMP operations.


Affected software

Cacti

How to mitigate CVE-2025-66399

Install updates from vendor's website.

Cacti - update to 1.2.29

External References

Related Security Bulletins