CyberRota Analysis
AI-GeneratedThe ntopng web-based network traffic monitoring application prior to version 6.7.260717 is vulnerable due to a lack of proper administrator checks in the edit_blacklist.lua script, allowing any authenticated user to manipulate critical parameters. This vulnerability enables non-admin users to redirect threat-intelligence downloads, disable blocklists, or disrupt scheduled updates, compromising the integrity and availability of the monitoring system. Organizations using ntopng should prioritize upgrading to version 6.7.260717 to mitigate these risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls lists_utils.editList for any authenticated user. The list_name, list_enabled, url, and list_update parameters allow a non-admin user to redirect threat-intelligence downloads to attacker-controlled content, disable blocklists, or prevent scheduled updates. The changes are persisted through Redis and reloaded without a lower-level authorization guard, undermining the integrity and availability of ntopng's threat-intelligence monitoring. This issue is fixed in version 6.7.260717.