CVE-2020-15874

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through a command injection in the /graph.php API endpoint.

Scoring

Severity
HIGH
CVSS base score
8.8
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS probability
1.12%
Published
2026-08-26
Last modified
2026-09-01

Affected products

Markdown version · Browse all CVEs