---
id: CVE-2025-34115
title: >-
  An authenticated command injection vulnerability exists in OP5 Monitor through
  version 7.1.9 via the 'cmd_str' parameter in the command_test.php endpoint
summary: >-
  An authenticated command injection vulnerability exists in OP5 Monitor through
  version 7.1.9 via the 'cmd_str' parameter in the command_test.php endpoint. A
  user with access to the web interface can exploit the 'Test this command'
  featur…
severity: high
cvss: 8.7
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-20
  - CWE-78
  - CWE-306
vendor: ITRS Group
product: OP5 Monitor
affected:
  - op5_monitor <= 7.1.9
published: '2025-07-15'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:17:25.700'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-34115'
references:
  - url: >-
      https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/http/op5_config_exec.rb
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/39676'
    label: disclosure@vulncheck.com
  - url: 'https://www.itrsgroup.com/products/network-monitoring-op5-monitor'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/op5-monitor-authenticated-command-execution
    label: disclosure@vulncheck.com
  - url: 'http://seclists.org/fulldisclosure/2026/Sep/38'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2025-07-15T13:39:43.767483Z'
cvssSource: cna
epss: 0.03551
epssPercentile: 0.88866
exploits:
  metasploit:
    - exploit/linux/http/op5_config_exec
  checkedAt: '2026-09-26T09:05:33.321Z'
ingestedAt: '2026-09-08T21:11:12.256Z'
---

## Overview

An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endpoint. A user with access to the web interface can exploit the 'Test this command' feature to execute arbitrary shell commands as the unprivileged web application user. The vulnerability resides in the configuration section of the application and requires valid login credentials with access to the command testing functionality. This issue is fixed in version 7.2.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
