CVE-2025-24367PoC(cacti / cacti)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch cacti cacti systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execution on the server. This vulnerability is fixed in 1.2.29.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-144

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cacti

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 7 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • General: 1 classified signal
  • Peaked 5d ago at 2 mentions (2026-01-31); latest day: 1
  • 7 total mentions across 6 days

Affected systems

Vendors
Products
cacti

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-01-31: 2Mentions · 2026-02-16: 1Mentions · 2026-05-23: 1Mentions · 2026-05-24: 1Mentions · 2026-05-25: 1Mentions · 2026-07-12: 1PoC Mentioned / Linked · 2026-01-31: 2PoC Mentioned / Linked · 2026-02-16: 1PoC Mentioned / Linked · 2026-05-24: 1PoC Mentioned / Linked · 2026-05-25: 1PoC Mentioned / Linked · 2026-07-12: 1Exploit Tool / Code · 2026-01-31: 2Patch / Workaround · 2026-01-31: 1Technical Details · 2026-01-31: 2Technical Details · 2026-02-16: 1Technical Details · 2026-05-23: 1Technical Details · 2026-05-24: 1Technical Details · 2026-05-25: 1Technical Details · 2026-07-12: 101-3102-1605-2305-2405-2507-12
Signal classification3 categories
PoC
457.1%
Exploit
228.6%
General
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-01-312
Exploit2
2026-02-161
PoC1
2026-05-231
General1
2026-05-241
PoC1
2026-05-251
PoC1
2026-07-121
PoC1
Full discourse7 posts
  • 0xdf@0xdf_
    General

    MonitorsFour from @hackthebox_eu features PHP type juggling to dump users, CVE-2025-24367 for RCE in Cacti, and CVE-2025-9074 to abuse the Docker Desktop API and mount the Windows host drive for root. Beyond Root: a shell on Windows." https://0xdf.gitlab.io/2026/05/23/htb-monitorsfour.html

    Post summary

    The tweet mentions two CVEs with basic details of RCE and API abuse but provides no PoC, exploit code, active exploitation claim, or patch information.

    312164234.9K
    26.6K followersView on X
  • ٱلطَّيِّبُ | Mustafa El Tayeb@T4T4R1S
    PoC

    MonitorsFour Pwned MonitorsFour features information disclosure via a vulnerable API endpoint to extract credentials from a .env file, exploitation of Cacti 1.2.28 using CVE-2025-24367 for remote code execution Writup: https://t4t4r1s.github.io/posts/monitor4/ https://t.co/Hw3PQonG7d

    Post summary

    The post announces that MonitorsFour is vulnerable and shares a write‑up link that presumably contains a proof‑of‑concept for exploiting CVE‑2025‑24367, but it does not detail active wild exploitation or provide exploit code or a patch.

    00020527
    329 followersView on X
  • Sakibul Ali Khan@sakibulalikhan
    PoC

    🎯 @hackthebox_eu machine #MonitorsFour [Easy] — Windows Box Pwned IDOR → creds leak Cacti RCE (CVE-2025-24367) → RCE Unauth Docker API → root PoC: https://labs.hackthebox.com/achievement/machine/777180/814 Chained misconfigs = full compromise. 💥 #Cybersecurity #OffensiveSecurity #HackTheBox #CTF #HTB https://t.co/gyLIGiUTBR

    Post summary

    The tweet announces a Hack The Box machine compromised via an IDOR, a Cacti RCE (CVE-2025-24367), and an unauthenticated Docker API, provides a PoC link, but lacks details on active exploitation or patching.

    00020135
    56 followersView on X
  • r0otk3r@r0otk3r
    PoC

    🚨 CVE-2025-24367: High-Severity 8.8 CVSS Cacti Authenticated RCE https://www.youtube.com/watch?v=Uuk20tau40I #Cybersecurity #Infosec #AppSec #RCE #Cacti #PHP #GraphTemplate #CVE202524367 #PoC #EthicalHacking #BugBounty #PatchNow https://t.co/Y7KGPVvhYp

    Post summary

    The tweet announces CVE‑2025‑24367, highlights its high severity and RCE vulnerability, and shares a PoC video, but lacks specific exploit code, patch details, or evidence of active exploitation.

    0001047
    43 followersView on X
  • Waqar Naeem@codewithpike
    PoC

    This was actually an easier box which was based on two CVES. One was Cacti rev shell CVE-2025-24367, while the other one was to escape the docker into host CVE-2025-9074. Learned how to escape docker and how to pragmatically use publicly available poc's. https://labs.hackthebox.com/achievement/machine/3238627/814

    Post summary

    The author notes that the Hack The Box challenge employed two CVEs, learned to escape Docker, and used publicly available POCs, but does not describe exploit code or active exploitation.

    00000197
    58 followersView on X
  • ThreatSynop@ThreatSynop
    Exploit

    🚨 New Metasploit Modules Weaponize Critical FreePBX, Cacti, and SmarterMail Flaws (Unauth RCE + Persistence) Metasploit 6.4.111 added seven modules chaining FreePBX auth bypass (CVE-2025-66039) with SQLi (CVE-2025-61675) or unrestricted upload (CVE-2025-61678) for unauth RCE, plus unauth RCE in Cacti <1.2.29 (CVE-2025-24367) and SmarterMail path traversal/file upload (CVE-2025-52691), alongside new persistence modules (Burp extension + SSH key injection). This matters because exploitation is now “push-button,” making rapid patching/segmentation and exposure validation urgent for internet-facing VoIP, monitoring, and mail servers. 🎯 Target: Global/Enterprise IT #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/metasploit-modules-target-freepbx-cacti-smartermail/

    Post summary

    The post announces that Metasploit 6.4.111 now contains modules enabling unauthenticated remote code execution against FreePBX, Cacti, and SmarterMail by chaining several CVEs. It emphasizes that exploitation is "push‑button," urging swift patching and segmentation.

    0000095
    196 followersView on X
  • ThreatSynop@ThreatSynop
    Exploit

    🚨 Metasploit Adds 7 Fresh Exploit Modules Targeting FreePBX, Cacti, and SmarterMail (Unauth RCE Chains) This Metasploit update ships new modules chaining FreePBX auth-bypass (CVE-2025-66039) with SQLi (CVE-2025-61675) or unrestricted upload (CVE-2025-61678) to reach unauth RCE, plus unauth RCE for Cacti <1.2.29 (CVE-2025-24367) and SmarterMail file upload/path traversal (CVE-2025-52691) to drop webshells/cron-based persistence. This matters because defenders can immediately validate exposure and prioritize patching/hardening for widely deployed VoIP, monitoring, and mail systems. 🎯 Target: Global/Enterprise IT #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/metasploit-exploit-modules/

    Post summary

    The post announces new Metasploit exploit modules for several CVEs that enable unauthenticated RCE and other attacks, urging immediate validation and patching.

    0000081
    196 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcacticacti---

Explore more