Description
PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the HTTP XML/REST Sensor.
Published: 2026-09-14
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Remote File Write
Action: Patch
AI Analysis

Impact

PRTG Network Monitor versions prior to 23.1.82 contain a flaw that allows a remote attacker to write to arbitrary files by sending specially crafted XML/REST requests to the HTTP interface. This remote file write capability could be used to overwrite configuration files or facilitate further compromise on the monitored host.

Affected Systems

The vulnerability affects Paessler PRTG Network Monitor releases older than 23.1.82. Any installation that has not been upgraded to 23.1.82 or later remains vulnerable.

Risk and Exploitability

The CVSS score of 2.7 indicates low severity. The EPSS score of < 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Because exploitation requires network access to the PRTG instance, exposure over the internet or to untrusted networks increases risk, but exposure on a secured internal network reduces the likelihood of an attack.

Generated by OpenCVE AI on September 15, 2026 at 16:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PRTG Network Monitor to version 23.1.82 or later to remove the flaw.
  • Restrict network traffic to the HTTP XML/REST Sensor with firewall rules or by limiting allowed IP addresses.
  • If the network sensor is not required, disable the HTTP XML/REST Sensor entirely to eliminate the attack surface.

Generated by OpenCVE AI on September 15, 2026 at 16:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Title Remote File Write via HTTP XML/REST Sensor in PRTG Network Monitor

Mon, 14 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Title PRTG Network Monitor Remote File Write via XML/REST Sensor

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title PRTG Network Monitor Remote File Write via XML/REST Sensor

Mon, 14 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Paessler
Paessler prtg Network Monitor
Weaknesses CWE-88
CPEs cpe:2.3:a:paessler:prtg_network_monitor:*:*:*:*:*:*:*:*
Vendors & Products Paessler
Paessler prtg Network Monitor
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


Mon, 14 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Description PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the HTTP XML/REST Sensor.
References

Subscriptions

Paessler Prtg Network Monitor
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T18:13:39.336Z

Reserved: 2023-01-05T00:00:00.000Z

Link: CVE-2023-22631

cve-icon Vulnrichment

Updated: 2026-09-14T14:56:38.430Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T04:16:33.853

Modified: 2026-09-22T20:00:03.713

Link: CVE-2023-22631

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:45:06Z

Weaknesses
  • CWE-88

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')