Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

🏠 Back to Blog

PRTG Network Monitor

Background

PRTG Network Monitor is agentless network monitoring software used to monitor bandwidth usage, uptime, and collect statistics from various network devices including routers, switches, servers, and more.

Key Information

  • First Released: 2003
  • Free Version Released: 2015 (limited to 100 sensors, 20 hosts)
  • Developer: Paessler GmbH (creating monitoring solutions since 1997)
  • Users Worldwide: ~300,000 (per company claims)
  • Deployment: AJAX-based web interface with desktop clients for Windows, Linux, and macOS

Supported Monitoring Protocols

  • ICMP
  • SNMP
  • WMI
  • NetFlow
  • REST API

Notable Organizations Using PRTG

  • Naples International Airport
  • Virginia Tech
  • 7-Eleven
  • Many other enterprises

Known Security Issues

PRTG has been assigned 26 CVEs over the years. Of these, only 4 have easily-found public exploits:

  • 2 Cross-Site Scripting (XSS) vulnerabilities
  • 1 Denial of Service (DoS) vulnerability
  • 1 Authenticated Command Injection vulnerability (CVE-2018-9276)

Prevalence in Assessments

While PRTG is rarely exposed externally, it is frequently encountered during internal penetration tests, making it an important target for post-compromise exploitation and lateral movement assessments.