CRITICAL🇵🇱 Wersja polska

CVE-2024-51092

CVSS 9.1v3.1pub. 2026-05-08upd. 2026-05-12

LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), SettingsController.php's update(), and PollDevice.php's initRrdDirectory().

🤖 AI Analysis
How it works

The vulnerability results from improper input validation in three locations in the application code: the index() method of AboutController.php, the update() method of SettingsController.php, and the initRrdDirectory() method of the PollDevice.php class. An attacker with an active account in LibreNMS can provide crafted data, which is then passed to system commands without proper sanitization (CWE-78), leading to execution of arbitrary OS commands on the server hosting the application. A public exploit module is available within the Metasploit framework for this vulnerability.

Impact

An attacker can execute arbitrary operating system commands in the context of the application process, which may lead to server takeover, data theft, backdoor installation, or further lateral movement in the network.

Mitigation & patch

LibreNMS should be immediately updated to version 24.10.0 or newer. Patch details are available in the official security advisory on GitHub (GHSA-x645-6pf9-xwxw). Until the update is applied, it is recommended to restrict access to the LibreNMS panel only to trusted networks and minimize the number of user accounts.

Who is affected

LibreNMS in all versions before 24.10.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
  • Librenms

    APP
    Librenms
    < 24.10.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCECommand Injection
CWE
References

Related vulnerabilities

CVE-2026-26988CRITICAL9.3PL ✓same product

SQL Injection w LibreNMS — endpoint ajax_table.php (wyszukiwanie IPv6)

CVE-2022-4070CRITICAL9.8PL ✓same product

LibreNMS — niewystarczające wygasanie sesji użytkownika (CWE-613)

CVE-2022-29712CRITICAL9.8PL ✓same product

LibreNMS — wielokrotny command injection w parametrach serwisowych

CVE-2021-44278CRITICAL9.8PL ✓same product

Path Traversal w LibreNMS – dostęp do arbitralnych plików

CVE-2019-10665CRITICAL9.8PL ✓same product

LibreNMS — wstrzyknięcie składni RRDtool przez parametry wykresów