Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitoring (Poller reload setup in the configuration modules) allows OS Command Injection.
On the poller parameters page, a user with high privilege is able to concatenate custom instructions into the poller reload command.
This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28.
References
Link | Resource |
---|---|
https://github.com/centreon/centreon/releases | Release Notes |
https://thewatch.centreon.com/latest-security-bulletins-64/cve-2025-5946-centreon-web-all-versions-high-severity-5104 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
22 Oct 2025, 14:08
Type | Values Removed | Values Added |
---|---|---|
First Time |
Centreon
Centreon centreon Web |
|
CPE | cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:* | |
References | () https://github.com/centreon/centreon/releases - Release Notes | |
References | () https://thewatch.centreon.com/latest-security-bulletins-64/cve-2025-5946-centreon-web-all-versions-high-severity-5104 - Vendor Advisory |
14 Oct 2025, 15:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-10-14 15:16
Updated : 2025-10-22 14:08
NVD link : CVE-2025-5946
Mitre link : CVE-2025-5946
CVE.ORG link : CVE-2025-5946
JSON object : View
Products Affected
centreon
- centreon_web
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')