← back
CVE-2018-20434

CVE-2018-20434

60Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 71%
from disclosure to weapon1 days
Published on NVDApr 24
1st PoC+1d
metasploitDec 16
exploitation probability
71%top 1% of all CVEs
observed exploitation
nono source reports it
5 public exploit(s)
LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to html/pages/addhost.inc.php during creation of a new device, and then making a /ajax_output.php?id=capture&format=text&type=snmpwalk&hostname=localhost request that triggers html/includes/output/capture.inc.php command mishandling.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.