CVE-2021-25297

nagios xi

Published 15 Feb 2021 · updated 9 Jul 2026 · Analyzed

8.8 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 18 Jan 2022, with a remediation deadline of 1 Feb 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.

References