PT-2026-84153 · Librenms · Librenms
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
LibreNMS versions prior to 26.5.0
Description
An authenticated administrator can achieve remote code execution via the
AboutController. The issue occurs because the snmpget configuration parameter is passed to the shell exec() function without proper validation. An attacker can modify the snmpget configuration to point to a malicious executable and trigger its execution by accessing the '/about' endpoint.Recommendations
Update to version 26.5.0 or later.
Restrict access to the '/about' endpoint to minimize the risk of exploitation.
Exploit
Fix
RCE
Command Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Librenms