CVE-2025-34280 - CVE House
Back to Database
Status published High CVE-2025-34280

Nagios Network Analyzer < 2024R2.0.1 RCE in LDAP Certificate Removal Function

Vulnerability Description

Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate removal operation fails to apply adequate input sanitation. An authenticated administrator can trigger command execution on the underlying host in the context of the web application service, resulting in remote code execution with the service's privileges.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-34280

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Haoyu Li
  • Shiwu Zhao
  • rmb122
  • rry
  • Xingchen Chen
  • Ru Tan
  • Qixu Liu

Affected Vendor

Affected Software

Network Analyzer
Vulnerable Versions:
0

Timeline

Official Publish: October 30th, 2025
Last Modified: November 17th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)