CVE-2025-24367

Cacti allows Arbitrary File Creation leading to RCE

Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execution on the server. This vulnerability is fixed in 1.2.29.


We have discovered 58 live websites that are affected by CVE-2025-24367.

Run a Free Instant Scan




Affected Software

Product  Cacti
Category Error and Exception Monitoring
Vulnerable Domains58 live websites (89% of Cacti install base)
Vulnerable Versions
  • from 0 through 1.2.28
Vulnerable Versions Count11 versions ( 85% of all versions)


Common Weakness Enumeration

CWE-144 Improper Neutralization of Line Delimiters



Details

  • Published - Jan 27, 2025
  • Updated - Nov 3, 2025

Website Distribution by Country

Number of websites using CVE-2025-24367
United States6 websites



Indonesia16 websites
Russia4 websites
Taiwan4 websites
Argentina3 websites
Spain2 websites
France2 websites
Lebanon2 websites
Romania2 websites
El Salvador2 websites

Website Distribution by TLD

Number of websites using CVE-2025-24367
.net16 websites
.com5 websites
.ru4 websites
.nl1 websites
.org.uk1 websites
.pl1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-24367

Top websites that are affected by CVE-2025-24367. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.net United States*,***,***
*******.*****.net Indonesia*,***,***
*************.******.****.cat Spain*,***,***
*****.*************.net United States*,***,***
*****.*********.ru Russia*,***,***
********.*********.net United States**,***,***
***.******.***.br Brazil**,***,***
**********.*****.net United States**,***,***
********.****.***.id Indonesia**,***,***
**********.***.ar Argentina**,***,***
See full domain list

FAQ

CVE-2025-24367 is Improper Neutralization of Line Delimiters in Cacti
A total of 58 websites have been identified as vulnerable to CVE-2025-24367, based on global website indexing conducted by WebTechSurvey.
The Cacti is affected by the CVE-2025-24367 vulnerability.
Cacti versions up to and including 1.2.28 are vulnerable to CVE-2025-24367.