在 LibreNMS 26.4.0 及更早版本中,系统会将管理员可配置的 Oxidized 集成接口(oxidized.url)返回的 JSON 字段(包括 name、ip、model、author、commit message)直接渲染到设备的 showconfig 页面,且未使用 htmlspecialchars() 进行转义。 若管理员将该 Oxidized URL 指向攻击者控制的服务器(SSRF 场景),攻击者可让该服务器返回包含恶意 JavaScript 的 JSON 数据,从而引发存储型/持久型跨站脚
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84194 | 8.6 HIGH | LibreNMS 23.10.0 before 26.4.0 OS Command Injection via Hostname |
| CVE-2026-84190 | 7.2 HIGH | LibreNMS before 26.5.0 Remote Code Execution via AboutController |
| CVE-2026-84192 | 7.1 HIGH | LibreNMS before 26.3.1 Stored XSS via SNMP/Syslog Data |
| CVE-2026-84191 | 6.1 MEDIUM | LibreNMS before 26.5.0 Stored XSS via SNMP VRF fields |
| CVE-2026-84193 | 5.8 MEDIUM | LibreNMS through 26.2.0 Stored Cross-Site Scripting via SNMP |
| CVE-2026-84188 | 4.8 MEDIUM | librenms before 26.7.0 Stored XSS via graph_descr settings |
No comments yet