ZeroHour

CVE-2025-32815

moderate

Hardcoded Credential Authentication Bypass in Infoblox NetMRI

CVSS 3.1
6.5 medium
EPSS
40%p99
Published
()
Modified
AI analysis

Infoblox NetMRI versions before 7.6.1 contain a hardcoded credential that allows an authentication bypass (CWE-287), letting an attacker log in to the appliance without a valid user account. The flaw is reachable over the network (AV:N) but requires no special privileges or user interaction, and its high attack complexity reflects that the attacker must be able to reach the NetMRI interface. Successful exploitation primarily compromises confidentiality of the network automation and change-management data stored in NetMRI, with a lower impact on integrity, consistent with its medium CVSS 3.1 score of 6.5. Any organization running NetMRI 7.6.0 or earlier is affected, typically enterprises using the appliance for network device configuration and change automation. No public proof-of-concept or confirmed in-the-wild exploitation is known, but the EPSS score of 39.7% (99th percentile) indicates a substantial probability of exploitation within the next 30 days.

What to do: Upgrade NetMRI to 7.6.1 or later, which removes the hardcoded credential. Until patched, restrict network access to the NetMRI management interface to trusted admin segments and review authentication logs for unexpected logins to built-in or service accounts. Because EPSS is elevated, prioritize patching even though the issue is not yet on CISA KEV and no public PoC exists.

Affected
Infoblox NetMRIAll versions prior to 7.6.1
Estimated exposure
moderatelikely thousands to tens of thousands of enterprise appliance deployments worldwide; internet-exposed instances unknown — NetMRI is a long-standing enterprise network-automation appliance commonly deployed inside corporate data centers alongside Infoblox DDI estates, but it is usually reachable only on management networks and no public install-base counts are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.

Vendors
infoblox
Products
netmri
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.