<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 23:28:11 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-290544</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-290544</link>
      <description>EUVD-2026-290544</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-290544</guid>
    </item>
    <item>
      <title>fkie_cve-2026-6204</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-6204</link>
      <description>&lt;p&gt;LibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary Locations config and the Netcommand feature. Successful exploitation requires administrative privileges. Exploitation could result in compromise of the underlying web server.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;LibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary Locations config and the Netcommand feature. Successful exploitation requires administrative privileges. Exploitation could result in compromise of the underlying web server.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-6204</guid>
    </item>
    <item>
      <title>GHSA-pr3g-phhr-h8fh — LibreNMS is Vulnerable to Remote Code Execution by Arbitrary File Write</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pr3g-phhr-h8fh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: librenms/librenms&lt;/p&gt;
&lt;p&gt;### Summary
A vulnerability has been identified that allows an authenticated administrator to execute arbitrary code on the host server. By modifying the binary path settings for built-in network tools and bypassing an input filter, an attacker with administrative privileges can download and execute malicious payloads.&lt;/p&gt;
&lt;p&gt;### Details
The application allows administrative users to configure the absolute binary paths for network diagnostic tools at `/settings/external/binaries`. This setting does not sufficiently validate ensuring the paths remain restricted to safe, intended executables. These tools are invoked by sending a request to the `GET /ajax/netcmd` endpoint. While there is an existing input filter designed to restrict arguments to valid IP addresses or hostnames, this filter can be bypassed.&lt;/p&gt;
&lt;p&gt;### PoC
To reproduce this vulnerability, a remote HTTP server should be hosted with a malicious script/executable, ensure the remote server is reachable by the server running LibreNMS. The PoC will use the file `malicious.sh` containing the following content. It will return the content of /etc/passwd and /etc/group, current working directory, username that is running the script, and it will list files of the current directory.&lt;/p&gt;
&lt;p&gt;```bash
#!/usr/bin/env bash&lt;/p&gt;
&lt;p&gt;cat /etc/passwd
cat /etc/group
whoami
pwd
ls
```&lt;/p&gt;
&lt;p&gt;1. Host a remote HTTP server that the server can reach and place the malicious script on the remote server. For demonstration, I will start it on localhost.
&amp;lt;img width=&amp;#34;593&amp;#34; heig…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: librenms/librenms&lt;/p&gt;
&lt;p&gt;### Summary
A vulnerability has been identified that allows an authenticated administrator to execute arbitrary code on the host server. By modifying the binary path settings for built-in network tools and bypassing an input filter, an attacker with administrative privileges can download and execute malicious payloads.&lt;/p&gt;
&lt;p&gt;### Details
The application allows administrative users to configure the absolute binary paths for network diagnostic tools at `/settings/external/binaries`. This setting does not sufficiently validate ensuring the paths remain restricted to safe, intended executables. These tools are invoked by sending a request to the `GET /ajax/netcmd` endpoint. While there is an existing input filter designed to restrict arguments to valid IP addresses or hostnames, this filter can be bypassed.&lt;/p&gt;
&lt;p&gt;### PoC
To reproduce this vulnerability, a remote HTTP server should be hosted with a malicious script/executable, ensure the remote server is reachable by the server running LibreNMS. The PoC will use the file `malicious.sh` containing the following content. It will return the content of /etc/passwd and /etc/group, current working directory, username that is running the script, and it will list files of the current directory.&lt;/p&gt;
&lt;p&gt;```bash
#!/usr/bin/env bash&lt;/p&gt;
&lt;p&gt;cat /etc/passwd
cat /etc/group
whoami
pwd
ls
```&lt;/p&gt;
&lt;p&gt;1. Host a remote HTTP server that the server can reach and place the malicious script on the remote server. For demonstration, I will start it on localhost.
&amp;lt;img width=&amp;#34;593&amp;#34; heig…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pr3g-phhr-h8fh</guid>
    </item>
  </channel>
</rss>
