Description
An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the searchPhrase parameter in the /ajax_table.php API endpoint. This affects as-selection.inc.php, edit-ports.inc.php, alertlog-stats.inc.php, alerts.inc.php, eventlog.inc.php, inventory.inc.php, ix-list.inc.php, ix-peers.inc.php, mempool-edit.inc.php, mempool.inc.php, poll-log.inc.php, processor-edit.inc.php, processor.inc.php, routing-edit.inc.php, sensors-common.inc.php, storage-edit.inc.php, storage.inc.php, and toner.inc.php (in includes/html/table). NOTE: some sources refer to this as CVE-2020-15876, but CVE-2020-15875 is the only correct CVE ID.
Published: 2026-09-13
Score: 5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Authenticated SQL Injection leading to full database exposure
Action: Immediate Patch
AI Analysis

Impact

An authenticated attacker with regular user privileges can leverage a SQL injection in the searchPhrase parameter of the /ajax_table.php API endpoint to read all data stored in the LibreNMS database. The flaw arises because input is concatenated into a query without proper sanitization (C attacker to read all information that the database holds.

Affected Systems

LibreNMS version 1.65 is affected. The vulnerability is present in PHP files that generate tables, including as-selection.inc.php, edit-ports.inc.php, alertlog-stats.inc.php, alerts.inc.php, eventlog.inc.php, inventory.inc.php, ix-list.inc.php, ix-peers.inc.php, mempool-edit.inc.php, mempool.inc.php, poll-log.inc.php, processor-edit.inc.php, sensors-common.inc.php, storage-edit.inc.php, storage.inc.php, and toner.inc.php.

Risk and Exploitability

The CVSS base score is 5.0, indicating moderate severity. The EPSS score is < 1%, implying a low probability of exploitation. It is not listed in CISA’s KEV catalog. Exploitation requires remote access to the web interface and an authenticated session with standard user rights. Because the SQL injection works via a public API endpoint, an attacker can first log in, send the crafted searchPhrase request, and read the database contents. There is no privilege escalation beyond the authenticated session, but the attacker can retrieve all stored data.

Generated by OpenCVE AI on September 15, 2026 at 17:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the LibreNMS 1.65.1 update which contains the fix for the /ajax_table.php SQL injection vulnerability.
  • If an upgrade is delayed, restrict access to the /ajax_table.php API to privileged users only or temporarily disable the searchPhrase feature to prevent exploitation.
  • Implement input validation with prepared statements or similar sanitization techniques to mitigate future injection risks.

Generated by OpenCVE AI on September 15, 2026 at 17:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Authenticated SQL injection in LibreNMS reveals entire database

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection via searchPhrase in LibreNMS 1.65
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection via searchPhrase in LibreNMS 1.65

Sun, 13 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the searchPhrase parameter in the /ajax_table.php API endpoint. This affects as-selection.inc.php, edit-ports.inc.php, alertlog-stats.inc.php, alerts.inc.php, eventlog.inc.php, inventory.inc.php, ix-list.inc.php, ix-peers.inc.php, mempool-edit.inc.php, mempool.inc.php, poll-log.inc.php, processor-edit.inc.php, processor.inc.php, routing-edit.inc.php, sensors-common.inc.php, storage-edit.inc.php, storage.inc.php, and toner.inc.php (in includes/html/table). NOTE: some sources refer to this as CVE-2020-15876, but CVE-2020-15875 is the only correct CVE ID.
First Time appeared Librenms
Librenms librenms
Weaknesses CWE-89
CPEs cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:*
Vendors & Products Librenms
Librenms librenms
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N'}


Subscriptions

Librenms Librenms
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T14:30:30.126Z

Reserved: 2020-07-21T00:00:00.000Z

Link: CVE-2020-15875

cve-icon Vulnrichment

Updated: 2026-09-14T14:29:37.539Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-13T19:16:51.627

Modified: 2026-09-22T19:56:19.073

Link: CVE-2020-15875

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:45:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')