Cross-site scripting in LibreNMS - #VU152690
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript in an authenticated user's browser.
The vulnerability exists due to improper output encoding in the wireless sensor description display in device/wireless.inc.php when rendering sensor descriptions obtained from SNMP DisplayString values. A remote attacker can supply a crafted SNMP DisplayString through a controlled monitored device's SNMP agent to execute arbitrary JavaScript in an authenticated user's browser.
An authenticated user must visit the affected device's Wireless tab after wireless sensor discovery or polling processes the crafted value.