VYPR

Pandora Fms

by Artica St

CVEs (1)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2025-340880.090.74Jul 3, 2025An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php functionality allows authenticated users to execute arbitrary OS commands via the select_ips parameter when performing network tools operations, such as pinging. This occurs because user input is not properly sanitized before being passed to system commands, enabling command injection.