Impact
An authenticated attacker with normal privileges can perform a SQL injection against the address parameter of the /ajax_table.php API endpoint in LibreNMS 1.65. The flaw allows execution of arbitrary SQL statements that can read the entire contents of the application database, exposing configuration data, device inventories, and potentially credential material. The vulnerability is a classic SQL injection (CWE‑89).
Affected Systems
The issue is specific to the LibreNMS 1.65 release. Only deployments running this exact version are affected; later releases such as 1.65.1 contain the fix.
Risk and Exploitability
The CVSS score of 8.8 signals high severity, while an EPSS score of < 1 % and the absence from the CISA KEV catalog indicate a low but non‑negligible likelihood that it might be actively exploited. The vulnerability requires remote authenticated access to the API, so privileged users or compromised accounts can exploit it. Due to the high impact combined with a low exploitation probability, operators should treat it with priority when updating systems.
OpenCVE Enrichment