CVE-2025-34088: Pandora FMS Authenticated Remote Code Execution via Ping Module
An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The nettools.php functionality allows authenticated users to execute arbitrary OS commands via the selectips parameter when performing network tools operations, such as pinging. This occurs because user input is not properly sanitized before being passed to system commands, enabling command injection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34088?
CVE-2025-34088 is classified as a high-severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-34088?
To mitigate CVE-2025-34088, upgrade to a version of Pandora FMS that is later than 7.0NG.
What is the impact of CVE-2025-34088?
The impact of CVE-2025-34088 allows authenticated users to execute arbitrary operating system commands.
Who is affected by CVE-2025-34088?
CVE-2025-34088 affects all authenticated users of Pandora FMS versions 7.0NG and earlier.
What component is vulnerable in CVE-2025-34088?
The net_tools.php functionality of Pandora FMS is the component that contains the vulnerability in CVE-2025-34088.