Cross-site scripting in LibreNMS - #VU152690

 

Cross-site scripting in LibreNMS - #VU152690

Published: September 28, 2026


Vulnerability identifier: #VU152690
CSH Severity: Medium
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary JavaScript in an authenticated user's browser.

The vulnerability exists due to improper output encoding in the wireless sensor description display in device/wireless.inc.php when rendering sensor descriptions obtained from SNMP DisplayString values. A remote attacker can supply a crafted SNMP DisplayString through a controlled monitored device's SNMP agent to execute arbitrary JavaScript in an authenticated user's browser.

An authenticated user must visit the affected device's Wireless tab after wireless sensor discovery or polling processes the crafted value.


Affected software

LibreNMS

Remediation

Install security update from vendor's website.

LibreNMS - update to 26.9.0

External References

Related Security Bulletins