CVE-2025-32814
moderateUnauthenticated SQL Injection in Infoblox NetMRI (< 7.6.1)
CVE-2025-32814 is a critical SQL injection flaw (CWE-89) in Infoblox NetMRI, the vendor's network automation and change-management appliance, affecting all versions prior to 7.6.1. Because the flaw is unauthenticated and network-reachable (CVSS:3.1 AV:N/PR:N), an attacker does not need credentials or user interaction to trigger it via the appliance's web interface. Successful injection can expose or alter the backend database, and the CVSS 9.8 score with high confidentiality, integrity, and availability impacts indicates attackers could read or modify sensitive inventory, configuration, and automation data and potentially disrupt the appliance's operation. Any organization running a NetMRI release earlier than 7.6.1 is affected. There is no confirmed in-the-wild exploitation, no public proof-of-concept, and it is not yet in CISA's KEV catalog, but the high EPSS score (36.4%, 98th percentile) suggests exploitation attempts are likely within 30 days.
What to do: Upgrade NetMRI to version 7.6.1 or later as the primary fix. Until patched, verify the appliance's management interface is not exposed to the internet or shared networks and restrict access to trusted admin networks. Monitor Infoblox advisories, since the elevated EPSS score suggests active exploitation may follow.
| Infoblox NetMRI | all versions before 7.6.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.
- Vendors
- infoblox
- Products
- netmri
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.