ZeroHour

CVE-2025-32814

moderate

Unauthenticated SQL Injection in Infoblox NetMRI (< 7.6.1)

CVSS 3.1
9.8 critical
EPSS
36%p98
Published
()
Modified
AI analysis

CVE-2025-32814 is a critical SQL injection flaw (CWE-89) in Infoblox NetMRI, the vendor's network automation and change-management appliance, affecting all versions prior to 7.6.1. Because the flaw is unauthenticated and network-reachable (CVSS:3.1 AV:N/PR:N), an attacker does not need credentials or user interaction to trigger it via the appliance's web interface. Successful injection can expose or alter the backend database, and the CVSS 9.8 score with high confidentiality, integrity, and availability impacts indicates attackers could read or modify sensitive inventory, configuration, and automation data and potentially disrupt the appliance's operation. Any organization running a NetMRI release earlier than 7.6.1 is affected. There is no confirmed in-the-wild exploitation, no public proof-of-concept, and it is not yet in CISA's KEV catalog, but the high EPSS score (36.4%, 98th percentile) suggests exploitation attempts are likely within 30 days.

What to do: Upgrade NetMRI to version 7.6.1 or later as the primary fix. Until patched, verify the appliance's management interface is not exposed to the internet or shared networks and restrict access to trusted admin networks. Monitor Infoblox advisories, since the elevated EPSS score suggests active exploitation may follow.

Affected
Infoblox NetMRIall versions before 7.6.1
Estimated exposure
moderateon the order of a few thousand enterprise appliance deployments — NetMRI is an enterprise network-automation appliance typically deployed once (or a few times) per organization on internal management networks rather than internet-facing, and Infoblox's automation customer base implies an installed base…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.

Vendors
infoblox
Products
netmri
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.