CVE-2025-32813
moderateUnauthenticated Command Injection in Infoblox NetMRI Appliances Before 7.6.1
CVE-2025-32813 is a command injection flaw (CWE-77) in Infoblox NetMRI, the vendor's network automation and configuration-management appliance, affecting all releases before version 7.6.1. A remote attacker can trigger it by sending crafted input containing unescaped shell metacharacters to the appliance, causing arbitrary operating-system command execution; note that the published description characterizes the flaw as unauthenticated, while the assigned CVSS vector (PR:H) lists high privileges as required. Successful exploitation yields high read, write, and availability impact on the appliance (C:H/I:H/A:H), and because NetMRI typically stores credentials for the network devices it manages, compromise could also expose those credentials and enable pivoting into managed infrastructure. Any organization running an affected NetMRI release is affected, though these appliances usually sit on internal management networks rather than the public internet. There is currently no confirmed in-the-wild exploitation, no known public proof-of-concept, and no CISA KEV listing, but EPSS assigns a high 43.9% probability of exploitation within 30 days.
What to do: Upgrade all NetMRI appliances to version 7.6.1 or later per Infoblox's advisory. Until patched, restrict network access to the NetMRI management interface with firewall rules or ACLs and review appliance logs for unexpected commands or logins. Verify the running version via the appliance UI/CLI to confirm whether your deployment is affected.
| Infoblox NetMRI | all versions before 7.6.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.
- Vendors
- infoblox
- Products
- netmri
- Weakness
- CWE-77
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.