ntopng 在 6.7.260717 之前的版本中,池(pools)批量删除端点未检查用户权限,使得经过身份验证的非管理员用户能够删除所有主机池及其成员绑定关系。攻击者可以向删除池端点发送 POST 请求,不可逆地销毁所有主机池,从而移除流量策略绑定和可见性限制,这可能绕过安全策略。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86098 | 7.4 HIGH | ntop nDPI before 6.0 Heap Buffer Overflow via ndpi_json_string_escape |
| CVE-2026-86090 | 7.1 HIGH | ntopng before 6.7.260717 Missing Authorization on the Notification Endpoint and Recipient |
No comments yet