CVE-2026-30480

A Local File Inclusion (LFI) vulnerability in the NFSen module (nfsen.inc.php) of LibreNMS 22.11.0-23-gd091788f2 allows authenticated attackers to include arbitrary PHP files from the server filesystem via path traversal sequences in the nfsen parameter.
Configurations

No configuration.

History

16 Apr 2026, 13:16

Type Values Removed Values Added
References () https://github.com/parlakbarann/CVE-2026-30480 - () https://github.com/parlakbarann/CVE-2026-30480 -
CWE CWE-98
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

14 Apr 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-14 15:16

Updated : 2026-06-17 10:32


NVD link : CVE-2026-30480

Mitre link : CVE-2026-30480

CVE.ORG link : CVE-2026-30480


JSON object : View

Products Affected

No product.

CWE
CWE-98

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')