LibreNMS Weak Password Policy Vulnerability

Vulnerability

A weak password policy vulnerability has been identified in LibreNMS versions prior to 25.11.0. This issue allows administrators to create user accounts with very weak and easily guessable passwords, such as '12345678'. As a result, the application is vulnerable to brute-force and credential stuffing attacks. The vulnerability arises because the user management feature does not enforce a strong password policy, allowing trivial passwords that compromise authentication security.

Impact

The weak password policy increases the risk of unauthorized access to user or administrative accounts, potentially leading to privilege escalation through compromised credentials. This vulnerability also degrades the overall security posture of the platform.

Reproduction

To reproduce this vulnerability, log in to LibreNMS with an administrator account. Navigate to the user management section and create a new user account, using '12345678' as the password. The application will accept this weak password and create the account without any restrictions.

Remediation

Users are advised to update to LibreNMS version 25.11.0 or later, and to enforce a strong password policy that includes a minimum of 12 characters with a mix of uppercase letters, lowercase letters, digits, and special characters. Additionally, commonly known weak passwords should be blocked.

Added: Nov 18, 2025, 11:18 PM
Updated: Nov 18, 2025, 11:18 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
5.0
exploitability
9.5
remediation
7.9
relevance
1.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.