Impact
LibreNMS releases older than 26.5.0 allow an authenticated administrator to trigger arbitrary command execution by manipulating the snmpget configuration string that is forwarded to a system shell without validation. The vulnerability utilizes a classic injection weakness, enabling the attacker to specify any executable path and have it run when a normal user requests the /about page. This flaw can result in full compromise of the host running LibreNMS, exposing all local data and services.
Affected Systems
Affected systems are installations of LibreNMS prior to version 26.5.0. The vulnerability is specific to the AboutController component of the web interface and will only be exploitable on sites where the administrator is authorized and the snmpget configuration can be edited via the UI.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity with remote execution potential. EPSS is not provided, so the current probability of exploitation is unknown; however, the flaw is only exploitable by logged-in administrators, which limits the attacker pool. Because the vulnerability is not listed in the CISA KEV catalog, it has not yet been associated with known exploits, but the knowledge of a remote code execution path warrants immediate attention.
OpenCVE Enrichment