Description
Centreon is a platform designed to monitor your cloud and on-premises infrastructure. This module exploits an command injection vulnerability using the `broker engine reload` setting on the poller configuration page of the Centreon web application. Injecting a malcious payload at the `broker engine reload` parameter and restarting the poller triggers this vulnerability. You need have admin access at the Centreon Web application in order to execute this RCE. This issue affects all Centreon editions >= `19.10.0` and it is fixed in Centreon Web versions `24.10.13`, `24.04.18` and `23.10.28`.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/linux/http/centreon/auth_rce_cve_2025_5946msf undefined(auth_rce_cve_2025_5946) > show actions ...actions...msf undefined(auth_rce_cve_2025_5946) > set ACTION < action-name >msf undefined(auth_rce_cve_2025_5946) > show options ...show and set options...msf undefined(auth_rce_cve_2025_5946) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub