Critical severity9.1GHSA Advisory· Published May 8, 2026· Updated May 12, 2026
CVE-2024-51092
CVE-2024-51092
Description
LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), SettingsController.php's update(), and PollDevice.php's initRrdDirectory().
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/librenms/librenms/security/advisories/GHSA-x645-6pf9-xwxwnvdExploitVendor Advisory
- raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/http/librenms_authenticated_rce_cve_2024_51092.rbnvdExploitThird Party Advisory
- github.com/advisories/GHSA-x645-6pf9-xwxwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-51092ghsa
News mentions
0No linked articles in our index yet.