Impact
An authenticated attacker who only requires normal user privileges in LibreNMS 1.65 can run arbitrary shell commands by exploiting a command injection flaw in the /graph.php API endpoint. This flaw allows the attacker to gain full system compromise, enabling data exfiltration, tampering, or further lateral movement by executing shell commands with the privileges of the web server process.
Affected Systems
The vulnerability affects LibreNMS 1.65. The CVE data does not list other versions as affected; no other vendors or products are identified.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, yet the high CVSS score of 8.8 indicates a severe risk. The vulnerability requires only normal authenticated access and allows arbitrary shell command execution over the network, providing full system compromise. The attack vector is remote, dependent on authorized credentials, making exploitation straightforward for anyone who can log in.
OpenCVE Enrichment