PT-2025-52519 · Unknown · Lilac-Reloaded For Nagios

Published

2025-12-19

·

Updated

2025-12-22

·

CVE-2023-53948

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lilac-Reloaded for Nagios version 2.0.8
Description The software contains a remote code execution issue in the autodiscovery feature. Attackers can inject arbitrary commands due to a lack of input filtering in the nmap binary parameter. Exploitation involves sending a crafted POST request to the autodiscovery endpoint, potentially allowing attackers to execute a reverse shell.
Recommendations Versions prior to 2.0.8 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2023-53948

Affected Products

Lilac-Reloaded For Nagios