CVE-2025-65014
Last modified
CVE-2025-65014 is a low-severity vulnerability rated 3.7/10 on the CVSS scale. LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a weak password policy vulnerability was identified in the user management functionality of the LibreNMS application. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a weak password policy vulnerability was identified in the user management functionality of the LibreNMS application. This vulnerability allows administrators to create accounts with extremely weak and predictable passwords, such as 12345678. This exposes the platform to brute-force and credential stuffing attacks. This issue has been patched in version 25.11.0.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Librenms | Librenms | < 25.11.0 |
References
- https://github.com/librenms/librenms/security/advisories/GHSA-5mrf-j8v6-f45gExploit, Mitigation, Vendor Advisory
- https://github.com/librenms/librenms/security/advisories/GHSA-5mrf-j8v6-f45gExploit, Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-65014?
How severe is CVE-2025-65014?
How do I fix CVE-2025-65014?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-65009In WODESYS WD-R608U router (also known as WDR122B V2.0 and W…7.1
- CVE-2025-6501A vulnerability, which was classified as critical, was found…9.8
- CVE-2025-65010WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR2…7.1
- CVE-2025-65011In WODESYS WD-R608U router (also known as WDR122B V2.0 and W…7.1
- CVE-2025-65012Kirby is an open-source content management system. From vers…5.4
- CVE-2025-65013LibreNMS is an auto-discovering PHP/MySQL/SNMP based network…6.1
- CVE-2025-65015joserfc is a Python library that provides an implementation …7.5
- CVE-2025-65017Decidim is a participatory democracy framework. In versions …6.5
- CVE-2025-65018LIBPNG is a reference library for use in applications that r…7.1
- CVE-2025-65019Astro is a web framework. Prior to version 5.15.9, when usin…6.1
- CVE-2025-6502A vulnerability has been found in code-projects Inventory Ma…9.8
- CVE-2025-65020Rallly is an open-source scheduling and collaboration tool. …6.5
Are you affected by CVE-2025-65014?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
