cbcvebase.
CVE-2025-22604
published 2025-01-27

CVE-2025-22604: Cacti is an open source performance and fault management framework. Due to a flaw in multi-line SNMP result parser, authenticated users can inject malformed…

PriorityP350high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
5.29%
91.7th percentile
Cacti is an open source performance and fault management framework. Due to a flaw in multi-line SNMP result parser, authenticated users can inject malformed OIDs in the response. When processed by ss_net_snmp_disk_io() or ss_net_snmp_disk_bytes(), a part of each OID will be used as a key in an array that is used as part of a system command, causing a command execution vulnerability. This vulnerability is fixed in 1.2.29.

Affected

7 ranges
VendorProductVersion rangeFixed in
cacticacti< 1.2.291.2.29
cacticacti<= 1.2.8
cacticacti>= 0 < 1.2.16+ds1-2+deb11u51.2.16+ds1-2+deb11u5
cacticacti>= 0 < 1.2.24+ds1-1+deb12u51.2.24+ds1-1+deb12u5
cacticacti>= 0 < 1.2.28+ds1-41.2.28+ds1-4
cacticacti>= 0 < 1.2.28+ds1-41.2.28+ds1-4
debiancacti< cacti 1.2.24+ds1-1+deb12u5 (bookworm)cacti 1.2.24+ds1-1+deb12u5 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerable functions are ss_net_snmp_disk_io() and ss_net_snmp_disk_bytes() — monitor for anomalous or malformed OID values being processed by these Cacti functions, as a portion of the OID is used as an array key in a system command
  • The attack vector is injection of malformed OIDs in multi-line SNMP responses — inspect SNMP poll results ingested by Cacti for unexpected characters or shell metacharacters embedded within OID strings
  • ·Exploitation requires authentication — prioritize monitoring authenticated Cacti user sessions and restrict SNMP data source permissions to trusted users only
  • ·Fixed in Cacti 1.2.29 upstream; Debian-specific fixes vary by release (bookworm: 1.2.24+ds1-1+deb12u5, bullseye: 1.2.16+ds1-2+deb11u5, forky/sid/trixie: 1.2.28+ds1-4) — verify the exact installed package version matches the patched version for your distribution

CVSS provenance

nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
osv7.2HIGH
vendor_debian9.1CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.