OS Command Injection in Pandora FMS by Pandora FMS
CVE-2025-5306

7HIGH

Key Information:

Vendor
CVE Published:
27 June 2025

What is CVE-2025-5306?

An OS command injection vulnerability has been identified in Pandora FMS, specifically attributable to improper sanitization of data within the Netflow directory field. This flaw can potentially allow attackers to execute arbitrary commands on the server by manipulating inputs, compromising system integrity and security. Affected versions include Pandora FMS from 774 to 778, highlighting the need for immediate attention and remediation to prevent exploitation.

Affected Version(s)

Pandora FMS all 774 <= 778

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Martin Sutovsky, Security Researcher. Rapid 7
.
CVE-2025-5306 : OS Command Injection in Pandora FMS by Pandora FMS