Impact
LibreNMS’s Virtualization Discovery module allows an authenticated administrator to perform command line injection, enabling arbitrary code execution on the host server. The vulnerability arises from insufficient input validation of commands processed by the module, making the system highly susceptible to exploitation. The impact is full compromise of the server, providing an attacker with the same privileges as the admin user.
Affected Systems
The affected product is LibreNMS from the vendor librenms. No specific version range is listed in the data, so any installation that includes the Virtualization Discovery module and grants authenticated admin users access is potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity level. EPSS data is unavailable, so the current likelihood of exploitation is undetermined, but the vulnerability is listed as not in the CISA KEV catalog, suggesting no known active exploits yet. The attacker would need authenticated admin access; once logged in, the command line injection can be triggered through the module’s input fields. This yields remote code execution with no apparent restriction on the commands that can be run.
OpenCVE Enrichment