CVE-2025-24367
8.8
HIGH
CVSS 3.1
EPSS 87.9%
Description
Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execution on the server. This vulnerability is fixed in 1.2.29.
How to fix CVE-2025-24367
To remediate CVE-2025-24367, upgrade the affected package to a fixed version below.
- Debian/cacti—upgrade to 1.2.16+ds1-2+deb11u5 or later
Is CVE-2025-24367 being exploited?
Likely — EPSS is 87.9%, placing CVE-2025-24367 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (1)
- from 0, < 1.2.16+ds1-2+deb11u5
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |