LibreNMS 是一种网络监控系统。在 21.6.0 至 26.5.0 版本中,Signal 告警传输模块存在命令注入漏洞,原因是 signal-cli 的执行路径以及告警传输配置中的“Recipient”(接收者)字段在传递给 调用前未进行充分转义。经过身份验证的管理员可以构造一个传输条目,使其“Recipient”字段包含 shell 元字符,并将路径指向捆绑的 脚本;该脚本本身会将攻击者可控的输入传递给其他不安全的 调用。通过将这些调用串联起来,管理员可以在 LibreNMS 主机上执行任意操作系统命令。该
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80214 | 8.6 HIGH | LibreNMS Virtualisation Discovery Module RCE |
| CVE-2026-45694 | 5.4 MEDIUM | LibreNMS: Reflected XSS in the Proxmox app view via unsanitized instance/vmid parameters |
No comments yet