CVE-2025-24367
Cacti allows Arbitrary File Creation leading to RCE
- Published
- Jan 27, 2025
- Updated
- Nov 3, 2025
- Assigning CNA
- GitHub_M
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XHigh · next 30 days
- Percentile
- 99.0%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execution on the server. This vulnerability is fixed in 1.2.29.
Sources
7- CVE-2025-24367Exploit
Authenticated remote code execution exploit for Cacti graph template vulnerability, with reverse shell payload and proxy support for authorized penetration testing.
- CVE-2025-24367-Cacti-PoCExploit
Proof of Concept for CVE-2025-24367
- CVE-2025-24367-Cacti-ExploitExploit
Script hecho para obtener una webshell gracias a la vulnerabilidad de cacti CVE-2025-24367 en su versión 1.2.28.
- monitorsfourResearch
HackTheBox MonitorsFour walkthrough covering credential leak, CVE-2025-24367 Cacti RCE, and CVE-2025-9074 Docker Desktop API container escape to root.
- CVE-2025-24367Exploit
CVE-2025-24367: Cacti AuthN Graph Template RCE in posix sh
- CVE-2025-24367Exploit
CVE-2025-24367 - Cacti Authenticated Graph Template RCE
- CVE-2025-24367-PoC-CactiExploit
Authenticated RCE PoC for Cacti (CVE‑2025‑24367). Uses graph template injection to write and execute a payload via the “Unix – Logged in Users” template. Intended for labs and controlled testing only.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.