
Proof-of-concept exploit for authenticated OS command injection (CWE-78) in Cacti ≤1.2.30, achieving remote code execution with CVSS 7.2.
Vulnerability Report: Authenticated RCE Data InputResearcher: K | Product: Cacti
≤ 1.2.30
[01] Vulnerability Summary| Field | Value |
|---|---|
| Product | Cacti — Complete RRDtool-based Graphing Solution |
| Affected Version(s) | ≤ 1.2.30 |
| Vulnerability Type | OS Command Injection (CWE-78) |
| Attack Vector | Network (authenticated admin) |
| Authentication | Yes — Administrator account required |
| Target OS | Windows (both vectors) + Linux (direct input_string vector) |
| CVSSv3.1 Score | 7.2 HIGH |
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
[02] Reference