Impact
ntopng contains two REST v2 endpoints that allow deleting or renaming tags without checking the privilege of the caller. Any authenticated user, even one without administrative rights, can target these actions to remove or alter any tag in the system. This enables an unprivileged user to disrupt network monitoring configurations, disguise traffic by renaming tags, or remove audit markers created by administrators, resulting in loss of visibility and potential abuse of the monitoring platform.
Affected Systems
The affected vendor is ntop, specifically the ntopng application. All installations of ntopng from version 6.7.0 up to and including 6.7.260717 are vulnerable. The vendor released a fix in version 6.7.260718.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high impact potential. No EPSS score is available, so the exact likelihood of exploitation is unquantified, but the flaw is active in a large set of releases. The vulnerability is not listed in the CISA KEV database at present. The likely attack path involves any database-hopping authenticated user sending a POST request to the exposed REST endpoints; no special network privileges or additional exploits are required beyond legitimate credentials.
OpenCVE Enrichment