Impact
An authenticated attacker who only requires normal user privileges in LibreNMS 1.65 can run arbitrary shell commands by exploiting a command injection flaw in the /graph.php API endpoint. This flaw allows the attacker to gain full system compromise, enabling data exfiltration, tampering, or further lateral movement by executing shell commands with the privileges of the web server process.
Affected Systems
The vulnerability affects LibreNMS 1.65. The CVE data does not list other versions as affected; no other vendors or products are identified.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not in the CISA KEV catalog, but the lack of a public exploit list does not reduce its potential impact because it requires only normal authentication and would allow arbitrary code execution over the network. The attack vector is remote, relying on authenticated access, and the vulnerability would be straightforward to exploit for anyone who can log in.
OpenCVE Enrichment