Authentication

Both platforms gate their web interface with a password, and access is usually gained through default or weak credentials. LibreNMS creates an admin account at install whose password is operator-chosen and often weak or reused; Observium ships with a documented default (admin/admin in its setup) that is frequently unchanged. Neither enforces a strong policy by default on older versions. A web login grants the monitoring view and the device/data-source configuration where the SNMP strings and credentials are stored, and reaches the authenticated features that the command-injection vulnerabilities exploit, so credentials are the access step before both harvesting and RCE.

bash
# Observium default
curl -sk -c cj https://<target>/ --data 'username=admin&password=admin'
# LibreNMS form login (CSRF token in the login page)
curl -sk -c cj https://<target>/login                       # grab _token
curl -sk -b cj -c cj https://<target>/login --data '_token=<t>&username=admin&password=<pw>'
# spray weak/reused passwords against the identified product

Exploitation notes#

  • Try the product's defaults (admin/admin on Observium; the install admin on LibreNMS) and weak/reused passwords; no strong policy on older versions makes spraying effective.
  • Admin access unlocks credential harvesting (stored device credentials) and the authenticated command-injection paths to RCE.
  • LibreNMS also issues API tokens; a found token authenticates to the API directly, bypassing the form.
  • A login is the common precondition for both follow-ons; non-admin accounts have limited reach.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more