Impact
The vulnerability in ntopng allows any authenticated user that is not an administrator to list and download system‑configuration backups. The backup files contain sensitive information such as password hashes, API tokens, TOTP secrets, and WebAuthn credentials. Access to these items can enable an attacker to compromise local user accounts and gain wider access within the monitored network, effectively turning a non‑admin presence into a privilege‑escalation vector.
Affected Systems
ntop:ntopng is affected in all releases older than 6.7.260718. The issue resides in the scripts/lua/rest/v2/get/system/configurations list and download endpoints, which were left unprotected. Affected deployments include any installation that has not applied the recent update that fixes the authorization check.
Risk and Exploitability
The CVSS score of 8.8 highlights a high severity. There is no EPSS data, and the vulnerability is not yet listed in the CISA KEV catalog, suggesting that it may not have seen widespread exploitation yet. Nevertheless, the necessary conditions are minimal: an authenticated non‑admin user and network access to the REST API. Once the backup is downloaded, the attacker can analyze the contents offline and leverage the extracted credential material to elevate privileges or compromise additional systems.
OpenCVE Enrichment