← Vulnerability feed

Vulnerability record · CVE-2019-10669 · published 9 September 2019

CVE-2019-10669: LibreNMS collectd graph command injection via weak escaping

Librenms · Librenms

LibreNMS through 1.47 passes user-supplied parameters in html/includes/graphs/device/collectd.inc.php through mysqli_real_escape_string, which does not escape shell metacharacters such as the backtick. The unsanitized value reaches the $rrd_cmd variable and is executed through passthru(), allowing OS command injection. The record does not state which later LibreNMS version fixes the flaw.

7.2 CVSS 3.1 High EPSS 81% · top 0.4% CWE-78 · OS command injection
7.2CVSS 3.1 base score, v2 6.5
81%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/device/collectd.inc.php where user supplied parameters are filtered with the mysqli_escape_real_string function. This function is not the appropriate function to sanitize command arguments as it does not escape a number of command line syntax characters such as ` (backtick), allowing an attacker to inject commands into the variable $rrd_cmd, which gets executed via passthru().

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityRemote command injection with public exploit references and a very high EPSS score, tempered by the high privilege level required to reach the vulnerable endpoint.

What it is

LibreNMS through 1.47 passes user-supplied parameters in html/includes/graphs/device/collectd.inc.php through mysqli_real_escape_string, which does not escape shell metacharacters such as the backtick. The unsanitized value reaches the $rrd_cmd variable and is executed through passthru(), allowing OS command injection. The record does not state which later LibreNMS version fixes the flaw.

Impact

An attacker with the required privileges can execute arbitrary operating system commands on the LibreNMS host, compromising confidentiality, integrity and availability of the server and any data it can reach.

Attack surface

The flaw is reachable over the network through the collectd device graph endpoint, but the CVSS vector (PR:H) indicates the attacker must already hold a high-privileged account; no user interaction is required.

Exploitation

CVE-2019-10669 is not listed in CISA KEV, but public exploit write-ups are referenced (Packet Storm and DarkMatter Xen1th Labs) and EPSS is very high at roughly 0.81 (99.6th percentile), indicating elevated real-world exploitation likelihood.

What to do

  • Upgrade LibreNMS to a release after 1.47 that fixes the collectd graph command injection; the record does not name the fixed version, so confirm with the vendor.
  • If immediate upgrade is not possible, restrict access to the collectd graph endpoint and the LibreNMS web interface to trusted administrative networks.
  • Audit and reduce the number of accounts with the high privileges required to reach this endpoint, and enforce strong authentication.
  • Review the collectd.inc.php code path to ensure shell arguments are escaped with escapeshellarg() rather than mysqli_real_escape_string().

Detection

  • Monitor web server and application logs for requests to html/includes/graphs/device/collectd.inc.php containing shell metacharacters such as backticks, semicolons or pipes.
  • Alert on unexpected child processes spawned by the web server or PHP-FPM user, especially rrdtool or shell invocations with unusual arguments.
  • Baseline and monitor outbound network connections originating from the LibreNMS host for signs of post-exploitation activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-10669 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-4070Librenms insufficient session expiration vulnerabilityInsufficient Session Expiration in GitHub repository librenms/librenms prior to 22.10.0.EPSS 0.65%9.8CVE-2022-29712Librenms command injection vulnerabilityLibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip, hostname, and service_param parameters.EPSS 1.7%9.8CVE-2021-44278Librenms path traversal vulnerabilityLibrenms 21.11.0 is affected by a path manipulation vulnerability in includes/html/pages/device/showconfig.inc.php.EPSS 1.5%9.8CVE-2019-10665Librenms injection vulnerabilityAn issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/common.inc.php and html/includes…EPSS 1.5%9.8CVE-2018-20434LibreNMS addhost OS command injection via community parameterLibreNMS 1.46 fails to sanitize the $_POST['community'] parameter in html/pages/addhost.inc.php when creating a new device, and the value is later mi…EPSS 71%analysed9.3CVE-2026-26988Librenms sql injection vulnerabilityLibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below contain an SQL Injection vulnerability in th…EPSS 0.48%9.2CVE-2026-86426Librenms improper authentication vulnerabilityLibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endp…EPSS 3.9%9.1CVE-2024-51092Librenms os command injection vulnerabilityLibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), Settings…EPSS 7.2%

Source: NIST National Vulnerability Database (record CVE-2019-10669), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.