Back to Database
Status published
High
CVE-2025-5306
Command Injection in Netflow path
Vulnerability Description
Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue affects Pandora FMS 774 through 778
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-5306
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Martin Sutovsky, Security Researcher. Rapid 7
More from Pandora FMS
View All →CVE-2025-4678
Remote Code Execution leads to Command Injection
High
7
CVE-2025-4653
Remote Code Execution leads to Command Injection
High
7
CVE-2024-9987
SQL Injection in CSV Module Data Collection
High
8.6
CVE-2024-35308
Post-auth Arbitrary File Read in the Server Plugins Section
High
8.3
CVE-2024-35307
Argument Injection Leading to Remote Code Execution in Realtime Graph Extension
Critical
9.4
Affected Vendor
Pandora FMS
View all reports →Affected Software
Pandora FMS
Vulnerable Versions:
774
Timeline
Official Publish:
June 27th, 2025
Last Modified:
June 27th, 2025
Added to House:
July 22nd, 2026