ZeroHour

CVE-2025-32813

moderate

Unauthenticated Command Injection in Infoblox NetMRI Appliances Before 7.6.1

CVSS 3.1
7.2 high
EPSS
44%p99
Published
()
Modified
AI analysis

CVE-2025-32813 is a command injection flaw (CWE-77) in Infoblox NetMRI, the vendor's network automation and configuration-management appliance, affecting all releases before version 7.6.1. A remote attacker can trigger it by sending crafted input containing unescaped shell metacharacters to the appliance, causing arbitrary operating-system command execution; note that the published description characterizes the flaw as unauthenticated, while the assigned CVSS vector (PR:H) lists high privileges as required. Successful exploitation yields high read, write, and availability impact on the appliance (C:H/I:H/A:H), and because NetMRI typically stores credentials for the network devices it manages, compromise could also expose those credentials and enable pivoting into managed infrastructure. Any organization running an affected NetMRI release is affected, though these appliances usually sit on internal management networks rather than the public internet. There is currently no confirmed in-the-wild exploitation, no known public proof-of-concept, and no CISA KEV listing, but EPSS assigns a high 43.9% probability of exploitation within 30 days.

What to do: Upgrade all NetMRI appliances to version 7.6.1 or later per Infoblox's advisory. Until patched, restrict network access to the NetMRI management interface with firewall rules or ACLs and review appliance logs for unexpected commands or logins. Verify the running version via the appliance UI/CLI to confirm whether your deployment is affected.

Affected
Infoblox NetMRIall versions before 7.6.1
Estimated exposure
moderateroughly 1,000-10,000 appliance deployments worldwide (estimate) — NetMRI is an enterprise-only network automation appliance typically deployed as a single unit or small cluster per large organization, implying a global installed base in the low thousands rather than internet-scale, and most instances are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.

Vendors
infoblox
Products
netmri
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.