{"id":"CVE-2025-34088","title":"An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier","summary":"An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php functionality allows authenticated users to execute arbitrary OS commands via the select_ips parameter when performin…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-78"],"vendor":"pandorafms","product":"pandora_fms","affected":["pandora_fms <= 7.0_ng"],"published":"2025-07-03","updated":"2026-07-14","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-34088","references":[{"url":"https://github.com/pandorafms/pandorafms","label":"disclosure@vulncheck.com"},{"url":"https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/http/pandora_ping_cmd_exec.rb","label":"disclosure@vulncheck.com"},{"url":"https://vulncheck.com/advisories/pandora-fms-rce-via-ping","label":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/48334","label":"disclosure@vulncheck.com"},{"url":"https://www.rapid7.com/db/modules/exploit/linux/http/pandora_ping_cmd_exec/","label":"disclosure@vulncheck.com"}],"tags":["nvd","exploit-available"],"epss":0.07345,"epssPercentile":0.94125,"ingestedAt":"2026-07-15T13:44:02.798Z","exploits":{"metasploit":["exploit/linux/http/pandora_ping_cmd_exec"],"checkedAt":"2026-09-24T07:52:53.273Z"},"exploitAvailable":true,"slug":"CVE-2025-34088","body":"## Overview\n\nAn authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php functionality allows authenticated users to execute arbitrary OS commands via the select_ips parameter when performing network tools operations, such as pinging. This occurs because user input is not properly sanitized before being passed to system commands, enabling command injection.\n\n## Affected\n\n- `pandora_fms <= 7.0_ng`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":62,"depthScoreParts":{"impact":48.4,"likelihood":1.5,"exploitation":12,"ransomware":0},"changes":[{"seq":4813,"id":"CVE-2025-34088","ts":1788887208337,"field":"exploit_available","old":"false","new":"true"},{"seq":3696,"id":"CVE-2025-34088","ts":1788886325420,"field":"exploit_available","old":"true","new":"false"},{"seq":2541,"id":"CVE-2025-34088","ts":1788883007005,"field":"exploit_available","old":"false","new":"true"},{"seq":1570,"id":"CVE-2025-34088","ts":1788882407259,"field":"exploit_available","old":"true","new":"false"},{"seq":684,"id":"CVE-2025-34088","ts":1788881843973,"field":"exploit_available","old":"false","new":"true"}]}