Code Injection Vulnerability in Nagios Log Server
CVE-2025-34277

9.4CRITICAL

Key Information:

Vendor

NagiOS

Vendor
CVE Published:
30 October 2025

What is CVE-2025-34277?

Nagios Log Server versions before 2024R1.3.1 are susceptible to a code injection vulnerability. This issue arises when malformed dashboard ID values are inadequately validated and then transmitted to an internal API. If an attacker provides specially crafted dashboard ID values, they can manipulate the system and execute arbitrary code within the Log Server process, potentially compromising security and data integrity.

Affected Version(s)

Log Server 0 < 2024R1.3.1

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Institute of Information Engineering, CAS
.
CVE-2025-34277 : Code Injection Vulnerability in Nagios Log Server