LibreNMS (an actively developed fork of Observium) and Observium are PHP-based network monitoring platforms that discover and poll devices largely over SNMP, storing their credentials to do so. Both are attacked the same way. The web interface authenticates with a password and has default and weak-credential exposure. Once authenticated, both have had command-injection vulnerabilities in features that build shell commands from user input, reaching code execution on the monitoring host. And both store the SNMP community strings and device credentials they use to poll, so harvesting those yields access to every monitored device. The platform compromise therefore cascades into the network it watches.
curl -sk https://<target>/ | grep -iE 'librenms|observium' # fingerprint
Subtopics#
- Enumeration: product and version fingerprinting.
- Authentication: default and weak credentials.
- Command injection: the authenticated RCE paths.
- Credential harvesting: stored SNMP strings and device credentials.