CVE-2026-30480
MEDIUMLibreNMS 22.11.0-23-gd091788f2 - LFI
Title source: llmDescription
A Local File Inclusion (LFI) vulnerability in the NFSen module (nfsen.inc.php) of LibreNMS 22.11.0-23-gd091788f2 allows authenticated attackers to include arbitrary PHP files from the server filesystem via path traversal sequences in the nfsen parameter.
References (1)
Scores
CVSS v3
6.5
EPSS
0.0003
EPSS Percentile
10.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-98
Status
published
Published
Apr 14, 2026
Tracked Since
Apr 14, 2026