peter bassill · operator
$ cve CVE-2018-20434 JSON

CVE-2018-20434 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 71.5% (pctl 99)

Patch early

A public exploit exists.

Description

LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to html/pages/addhost.inc.php during creation of a new device, and then making a /ajax_output.php?id=capture&format=text&type=snmpwalk&hostname=localhost request that triggers html/includes/output/capture.inc.php command mishandling.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS71.49% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploityes
Published2019-04-24
Last modified2026-06-17

Affected (1)

VendorProduct
librenmslibrenms

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD