PT-2025-41936 · Centreon · Centreon Infra Monitoring

Published

2025-10-14

·

Updated

2025-10-14

·

CVE-2025-5946

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Centreon Infra Monitoring versions 23.10.0 through 23.10.28 Centreon Infra Monitoring versions 24.04.0 through 24.04.18 Centreon Infra Monitoring versions 24.10.0 through 24.10.13
Description A flaw exists in Centreon Infra Monitoring related to improper neutralization of special elements in OS commands, specifically an OS Command Injection. This issue occurs in the Poller reload setup within the configuration modules. A user with high privileges can inject custom instructions into the poller reload command.
Recommendations Update Centreon Infra Monitoring to version 23.10.28 or later. Update Centreon Infra Monitoring to version 24.04.18 or later. Update Centreon Infra Monitoring to version 24.10.13 or later.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-5946

Affected Products

Centreon Infra Monitoring