logo

Being Stubborn Pays Off pt. 2 – Tale of two 0days on PRTG Network Monitor

ID: 7bf7ba22-5300-54a0-a665-2976e2ba719a

STIX ID: report--7bf7ba22-5300-54a0-a665-2976e2ba719a

Feed Name: SensePost Blog

Threat Score
80/100

Date Published: 2020-05-22

Date Updated: 2026-04-30

...
...

This analysis documents two PRTG Network Monitor flaws—CVE-2019-11074 (arbitrary file write/DoS via PhantomJS-based sensor) and CVE-2019-11073 (remote code execution as SYSTEM via argument-injection in the HTTP Transaction Sensor)—provides step-by-step exploitation detail and proof-of-concept techniques, highlights that exploitation requires administrative credentials (often default), and notes remediation was released in version 19.3.51 while observing many Internet-exposed instances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.