Description
A Local File Inclusion (LFI) vulnerability in the NFSen module (nfsen.inc.php) of LibreNMS 22.11.0-23-gd091788f2 allows authenticated attackers to include arbitrary PHP files from the server filesystem via path traversal sequences in the nfsen parameter.
Published: 2026-04-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local File Inclusion that allows authenticated users to include arbitrary PHP files
Action: Update
AI Analysis

Impact

A Local File Inclusion vulnerability exists in the NFSen module of LibreNMS. The flaw allows an authenticated attacker to supply path‑traversal sequences in the nfsen parameter, causing the application to include arbitrary PHP files from the server filesystem. Including an arbitrary PHP file could expose sensitive configuration data or other information stored on the host. The weakness is characterized by CWE-98.

Affected Systems

The vulnerability appears in LibreNMS build 22.11.0‑23-gd091788f2 and any preceding or equivalent builds that contain the vulnerable nfsen.inc.php handler with the NFSen module enabled. Deployments that have removed or disabled the NFSen module are not vulnerable.

Risk and Exploitability

The exploit requires valid credentials to allow a user to submit the nfsen parameter. The vulnerability is an LFI that does not require elevated privileges or kernel level access, making it relatively straightforward for an attacker with access. The CVSS score is 6.5 and the EPSS score is less than 1%, indicating a moderate severity with low probability of exploitation; the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated web request that manipulates the nfsen parameter with path‑traversal sequences. Based on the description, it is inferred that the attacker could read or include sensitive files, though concrete execution impact is not confirmed in the payload.

Generated by OpenCVE AI on April 18, 2026 at 09:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a LibreNMS update newer than build 22.11.0‑23
  • Disable the NFSen module if an update is not immediately possible
  • Restrict the nfsen parameter to allow only whitelisted file names
  • Enforce strong, unique passwords for all user accounts to reduce the risk of authenticated exploitation
  • Monitor log files for anomalous inclusion attempts and audit file access patterns

Generated by OpenCVE AI on April 18, 2026 at 09:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 18 Apr 2026 09:45:00 +0000

Type Values Removed Values Added
Title Authenticated LFI in LibreNMS NFSen Module Exposes Arbitrary PHP Files

Fri, 17 Apr 2026 09:15:00 +0000

Type Values Removed Values Added
Title Authenticated Local File Inclusion in LibreNMS NFSen Module
Weaknesses CWE-22

Thu, 16 Apr 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-98
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Apr 2026 16:00:00 +0000

Type Values Removed Values Added
Title Authenticated Local File Inclusion in LibreNMS NFSen Module
Weaknesses CWE-22

Tue, 14 Apr 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Librenms
Librenms librenms
Vendors & Products Librenms
Librenms librenms

Tue, 14 Apr 2026 14:30:00 +0000

Type Values Removed Values Added
Description A Local File Inclusion (LFI) vulnerability in the NFSen module (nfsen.inc.php) of LibreNMS 22.11.0-23-gd091788f2 allows authenticated attackers to include arbitrary PHP files from the server filesystem via path traversal sequences in the nfsen parameter.
References

Subscriptions

Librenms Librenms
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-04-16T12:06:38.149Z

Reserved: 2026-03-04T00:00:00.000Z

Link: CVE-2026-30480

cve-icon Vulnrichment

Updated: 2026-04-16T11:36:52.276Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-14T15:16:27.337

Modified: 2026-04-17T15:24:57.753

Link: CVE-2026-30480

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T09:30:25Z

Weaknesses