26.5.0 之前的 LibreNMS 在 VRF 显示页面中存在存储型跨站脚本(XSS)漏洞。该漏洞源于从 SNMP 轮询获取的 、 和 字段在未经验证和清理(sanitization)的情况下直接渲染。攻击者若能控制被监控的网络设备,便可通过 SNMP 响应注入任意 JavaScript 代码,该代码将在查看 VRF 相关页面的任何用户的浏览器中执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84194 | 8.6 HIGH | LibreNMS 23.10.0 before 26.4.0 OS Command Injection via Hostname |
| CVE-2026-84189 | 8.1 HIGH | LibreNMS before 26.7.0 Stored XSS via Oxidized API |
| CVE-2026-84190 | 7.2 HIGH | LibreNMS before 26.5.0 Remote Code Execution via AboutController |
| CVE-2026-84192 | 7.1 HIGH | LibreNMS before 26.3.1 Stored XSS via SNMP/Syslog Data |
| CVE-2026-84193 | 5.8 MEDIUM | LibreNMS through 26.2.0 Stored Cross-Site Scripting via SNMP |
| CVE-2026-84188 | 4.8 MEDIUM | librenms before 26.7.0 Stored XSS via graph_descr settings |
No comments yet