A Local File Inclusion (LFI) vulnerability in the NFSen module (nfsen.inc.php) of LibreNMS 22.11.0-23-gd091788f2 allows authenticated attackers to include arbitrary PHP files from the server filesystem via path traversal sequences in the nfsen parameter.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone proof-of-concept and advisory package for an authenticated Local File Inclusion/path traversal issue in LibreNMS's NFSen module, identified here as CVE-2026-30480. It is not an automated exploit tool or framework module; instead it documents the bug, shows the vulnerable PHP logic, and provides patched examples. Repository structure: 5 files total. Two PHP files contain code-like snippets: vulnerable_code.php reproduces the unsafe include logic from LibreNMS's includes/html/pages/device/nfsen.inc.php, and patched_code.php shows three remediation patterns (whitelist validation, basename sanitization, and regex validation). README.md is the main technical write-up with exploitation steps, affected versions, impact, and screenshots. SECURITY_ADVISORY.md is a condensed advisory. .gitignore is non-relevant housekeeping. Main exploit capability: an authenticated attacker can supply a crafted nfsen parameter to the Netflow/NFSen device page so that LibreNMS includes a different .inc.php file than intended. The demonstrated payload ../../api-access (URL-encoded as ..%2f..%2fapi-access) causes the application to resolve includes/html/pages/device/nfsen/../../api-access.inc.php, effectively including includes/html/pages/api-access.inc.php. This can expose unintended application content, trigger privileged page logic, and potentially support privilege escalation or broader impact depending on what include targets exist and how they behave. Attack surface: web/network. The documented vulnerable route is /device/{id}/tab=netflow with the nfsen parameter. Exploitation requires authentication and access to a device page with the Netflow/NFSen tab. The repository does not contain a scanner, brute forcer, shell payload, or post-exploitation automation; therefore maturity is best classified as POC. Notable observables include the vulnerable file path includes/html/pages/device/nfsen.inc.php, the include base directory includes/html/pages/device/nfsen/, the example target file includes/html/pages/api-access.inc.php, and the proof-of-concept URL pattern https://[TARGET]/device/[DEVICE_ID]/tab=netflow?nfsen=..%2f..%2fapi-access.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.