SQL Injection Vulnerability in LibreNMS Network Monitoring Tool
CVE-2025-65093

5.5MEDIUM

Key Information:

Vendor

Librenms

Status
Vendor
CVE Published:
18 November 2025

What is CVE-2025-65093?

A boolean-based blind SQL injection vulnerability exists in the LibreNMS application at the /ajax_output.php endpoint. This flaw allows attackers to directly manipulate SQL queries by injecting malicious input into the hostname parameter, which is not properly sanitized. As a result, attackers could infer sensitive data from the database through crafted conditional responses. This vulnerability was addressed in LibreNMS version 25.11.0, emphasizing the importance of secure coding practices to prevent direct SQL manipulation.

Affected Version(s)

librenms < 25.11.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.