CVE-2025-32813
infoblox netmri Improper Neutralization of Special Elements used in a Command ('Command Injection')
Record summary
CVE-2025-32813 has a selected CVSS score of 7.2 (high); EIP currently links 1 curated repository PoC and 1 Nuclei template.
Description
An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 31, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated May 23, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
netmriBrowse infoblox / netmri | VulnCheck | Version data not supplied | |
Proofs of concept
1Curated repository PoCs
GitHubCVE-2025-32813Curated repository PoCby RhinoSecurityLabsStars: 905Not analyzed2 files
Nuclei templates
1ProjectDiscoveryHIGHInfoblox NetMRI < 7.6.1 - Unauthenticated Command Injection in get_saml_requestCVSS 7.2
An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.
Impact
Unauthenticated attackers can execute arbitrary operating system commands with elevated privileges through the saml_id parameter in the get_saml_request endpoint.
Remediation
Upgrade to Infoblox NetMRI version 7.6.1 or later that properly sanitizes user input in SAML request handling.
Source: ProjectDiscovery