27Oca
CVE-2025-22604 | Cacti up to 1.2.8 OID ss_net_snmp_disk_io/ss_net_snmp_disk_bytes os command injection (GHSA-c5j8-jxj3-hh36)
A vulnerability was found in Cacti up to 1.2.8. It has been classified as critical. Affected is the functionss_net_snmp_disk_io/ss_net_snmp_disk_bytes
of the component OID Handler. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2025-22604. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.