Description
PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor.
Published: 2026-09-14
Score: 2.7 Low
EPSS: n/a
KEV: No
Impact: Remote file write via FTP Server Count Sensor
Action: Patch
AI Analysis

Impact

The flaw appears in the FTP Server Count Sensor component of PRTG before version 23.1.82, permitting an attacker to craft requests that result in arbitrary file creation or modification on the monitored host. Because the file system remains writable, an adversary could potentially create or alter configuration or log files, leading to further exploitation. The weakness maps to CWE‑88 (Resource Conflict or Race Condition).

Affected Systems

Paessler PRTG Network Monitor versions earlier than 23.1.82 are affected. The issue originates solely in the FTP Server Count Sensor module. Systems running the sensor without patch remain vulnerable.

Risk and Exploitability

The CVSS score of 2.7 indicates low severity, and without a publicly available exploit the probability of exploitation remains uncertain. However, the vulnerability enables remote attackers to write files from outside the system, which could serve as a foothold for further compromise, especially if the target user has elevated privileges. Because EPSS is not available and the vulnerability is not listed in KEV, it is unclear whether active exploitation is occurring. Administrators should consider the potential for privilege escalation when assessing exposure.

Generated by OpenCVE AI on September 14, 2026 at 11:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest PRTG Network Monitor update (23.1.82 or newer) to eliminate the file write capability.
  • Disable or remove the FTP Server Count Sensor from all monitored devices until a patch is available.
  • Restrict file system write permissions on the PRTG installation directories so that externally written files cannot overwrite critical configuration or system files.
  • Use network segmentation or firewall rules to limit exposure of the FTP Server Count Sensor to trusted networks.

Generated by OpenCVE AI on September 14, 2026 at 11:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title File Write Vulnerability in PRTG Network Monitor FTP Server Count Sensor

Mon, 14 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor.
First Time appeared Paessler
Paessler prtg Network Monitor
Weaknesses CWE-88
CPEs cpe:2.3:a:paessler:prtg_network_monitor:*:*:*:*:*:*:*:*
Vendors & Products Paessler
Paessler prtg Network Monitor
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Paessler Prtg Network Monitor
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T03:39:16.120Z

Reserved: 2023-01-05T00:00:00.000Z

Link: CVE-2023-22632

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T04:16:34.960

Modified: 2026-09-14T04:16:34.960

Link: CVE-2023-22632

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-14T12:00:14Z

Weaknesses
  • CWE-88

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')