CVE-2025-61304 Details
Description
OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address.
A command injection vulnerability has been identified in the Dynatrace ActiveGate ping extension, affecting versions prior to 1.016. This vulnerability allows for OS command injection via a crafted IP address. The ping extension utilizes the Windows command prompt to execute ping commands. The input field for the Test Target Host can accept up to 1024 characters, enabling the injection of additional commands for ActiveGate to execute by appending an '&' after the IP address.
Users are advised to update to Dynatrace ActiveGate ping extension version 1.016 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/pentastic-be/CVE-2025-61304 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| dynatrace activegate ping extension | <= 1.016 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 8, 2026 | Initial Analysis | [email protected] |
| Nov 5, 2025 | CVE Modified | CISA-ADP |
| Nov 5, 2025 | New CVE Received | [email protected] |