PT-2025-47404 · Librenms · Librenms
Published
2025-11-18
·
Updated
2025-11-19
·
CVE-2025-65014
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
LibreNMS versions prior to 25.11.0
Description
The user management functionality of LibreNMS fails to enforce a strong password policy, allowing administrators to create accounts with weak and predictable passwords, such as
12345678. This exposes the platform to brute-force and credential stuffing attacks. The vulnerable component is the user creation/password definition process. The application accepts trivial and well-known weak passwords without restrictions when creating new user accounts. This can lead to unauthorized access to user or administrative accounts and potential privilege escalation.Recommendations
Versions prior to 25.11.0: Update to version 25.11.0 or later.
Enforce a strong password policy, requiring a minimum of 12 characters with uppercase, lowercase, digits, and special characters.
Block the use of commonly known weak passwords, such as
12345678, password, admin, and qwerty.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Librenms