CVE-2025-5306
moderateAuthenticated OS command injection in Pandora FMS Netflow (CVE-2025-5306)
Pandora FMS versions 774 through 778 fail to properly neutralize special characters in the directory field of the Netflow feature, which allows OS command injection (CWE-77). An attacker who already holds high-privilege (administrative) access to the Pandora FMS console over the network can submit a crafted directory value, causing arbitrary operating system commands to run on the monitoring server. Successful exploitation yields a high integrity impact (full system modification and a shell-level foothold on the server), with low confidentiality and availability impact per the CVSS scoring. Organizations running affected Pandora FMS builds are affected, particularly those with internet-exposed consoles where an admin account compromise could be escalated to server-level control. No public proof-of-concept or in-the-wild exploitation is known yet, but the EPSS score of 32% (98th percentile) indicates a meaningful probability of exploitation attempts within the next 30 days.
What to do: Upgrade Pandora FMS to a release newer than build 778, checking Artica's security advisory for the specific fixed build. Until patched, restrict permission to modify Netflow settings to trusted administrators only and keep the console off the public internet or behind a VPN. Because exploitation requires high-privileged access, review recent activity on administrator accounts and enforce MFA and password rotation for console admins.
| Artica Pandora FMS | 774 through 778 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue affects Pandora FMS 774 through 778
- Vendors
- artica
- Products
- pandora fms
- Weakness
- CWE-77
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:D/RE:M/U:Green
In the news0 stories
No ingested article mentions this CVE yet.