Impact
An authenticated attacker with normal privileges can perform a SQL injection in the address parameter of the /ajax_table.php API endpoint in LibreNMS 1.65, allowing the extraction of all database information. The vulnerability is a typical SQL injection that bypasses input validation and permits an attacker to read sensitive data. The impact is total disclosure of the system’s entire database contents, which includes configuration, device inventories, and potentially credential material.
Affected Systems
The vulnerability is specific to the LibreNMS 1.65 version of the open‑source network monitoring platform. Any deployment running this exact release is affected.
Risk and Exploitability
No CVSS score is currently available for this CVE, but the required conditions are simple: the attacker must be authenticated and have normal user privileges. Since the exploit permits full database access, it is considered high risk. The EPSS score is not listed and the vulnerability is not in the CISA KEV catalog, so the likelihood of widespread exploitation is currently unknown but could be significant if the database is exposed over a network.
OpenCVE Enrichment