CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-34322: log server before 2026 (exclusive), 2026 · update r1; +1 more affected products

CVE-2025-34322. CVSS 3.1 base score 7.2 (HIGH, NVD). EPSS 0.09475 (percentile 0.95307), scored 2026-10-06.

Affected technology

log server · before 2026 (exclusive)
nagios

log server · 2026 · update r1
nagios

Log Server · 0 to before 2026R1.0.1
Nagios

Description’s affected range: versions prior to 2026R1.0.1

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · High privileges required · No user interaction required

What an attacker can do

An authenticated user with access to the 'Global Settings' page can supply crafted values in these fields to inject additional shell commands, resulting in arbitrary command execution as the 'www-data' user and compromise of the Log Server host. Vendor/CNA’s CVSS 4.0 assessment (base score 8.6/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-78
CCR priority
31.2 /100 (P4)
CVSS 3.1
7.2 /10 · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H · NVD
EPSS
0.09475 · percentile 0.95307 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-34322.html