S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-25296 Scanner

CVE-2021-25296 scanner - OS Command Injection vulnerability in Nagios XI

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-25296
8.8
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Nagios XI is an enterprise-level IT infrastructure monitoring solution used to detect and resolve IT infrastructure issues before they affect critical business processes. It provides complete monitoring of networks, servers, applications, and services, all through a single pane of glass. It is widely used by organizations that require high availability and uptime for their critical business operations.

Unfortunately, Nagios XI is not immune to vulnerabilities. One such vulnerability is CVE-2021-25296. This vulnerability exists in the file "/usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php" due to incorrect sanitization of user-controlled input. As a result, authenticated users can inject operating system commands, leading to OS command injection on the Nagios XI server.

The exploitation of CVE-2021-25296 can lead to grave consequences. Attackers can leverage the vulnerability to execute arbitrary commands on the remote server with the permissions of the Nagios XI user account. With the right privileges, this can result in information disclosure, data theft, or even complete control of the system.

s4e.io provides comprehensive security solutions for businesses of all sizes. Thanks to the pro features of the platform, users can quickly and easily discover vulnerabilities in their digital assets. It enables enterprises to gain complete visibility into their assets, monitor for vulnerabilities and emerging threats, and prioritize remediation efforts to prevent security incidents. By using this platform, businesses can stay ahead of cybercriminals and protect their critical assets from harm.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is recommended that Nagios XI administrators take the following precautions:

  • Upgrade to the latest version of Nagios XI (xi-5.8.6).
  • Implement strong access controls and authentication mechanisms.
  • Enforce least privilege principles for all user accounts.
  • Regularly scan the Nagios XI server for known vulnerabilities.
  • Deploy a robust intrusion detection and prevention system.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.