Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Critical Lack of Security Cacti (CVE-2025-22604) allows to execute the removed code
Global Security

Critical Lack of Security Cacti (CVE-2025-22604) allows to execute the removed code

AdminBy AdminJanuary 29, 2025No Comments2 Mins Read
Cacti Security Flaw
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


January 29, 2025Red LakshmananVulnerability / intelligence threats

Lack of security Cacti

Within the framework of the open source network monitoring, the CACTI malfunction and malfunction management was disclosed by a critical lack of safety, which can allow the assailant check to achieve remote code in sensitive instances.

The disadvantage, which is tracked as the CVE-2025-22604, carries the CVSS 9.1 with a maximum of 10.0.

“Due to the lack of many SNMP analysis, authentified users can enter the wrong OID in return,”-supports the project – Note In an advisory issue released this week.

“When processing ss_net_snmp_disk_io () or ss_net_snmp_disk_bytes () part of each OID will be used as a key in an array used within the system team that causes the team vulnerability.”

Successful vulnerability can allow the user conducted with the devices management permits to execute an arbitrary code on the server and steal, edit or delete sensitive data.

Cybersecurity

CVE-2025-22604 affects all versions of the software before and including 1.2.28. It was considered in version 1.2.29. A security researcher undergoing an online U32i -Pseudonym was enrolled in the detection and report.

Also addressed in the latest version Cve-2025-24367 (CVSS assessment: 7.2), which can allow the attacker check to create arbitrary PHP scenarios at the root of the application, abusing the graphics and the functionality of the schedule template, which will lead to the remote code.

With a safety vulnerability in cacti Having got into active operation In the past, organizations based on network monitoring software should put the use of the necessary patches to mitigate the risk of a compromise.

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025

Fedramp at starting speed: obtained lessons

June 18, 2025

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025

Ex-Analytics-Tsru, sentenced to 37 months for leaks of secret documents on national protection

June 18, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025

Fedramp at starting speed: obtained lessons

June 18, 2025

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025

Ex-Analytics-Tsru, sentenced to 37 months for leaks of secret documents on national protection

June 18, 2025

Iran slows the Internet to prevent cyber -napades against the background of escalation of regional conflict

June 18, 2025

RCE Critical Error RCE Rate 9.9 CVSS in Backup and Replication

June 18, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.