CVE-2025-32814
infoblox netmri Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Record summary
CVE-2025-32814 has a selected CVSS score of 9.8 (critical); EIP currently links 1 curated repository PoC and 1 Nuclei template.
Description
An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 22, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated May 22, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
netmriBrowse infoblox / netmri | VulnCheck | Version data not supplied | |
Proofs of concept
1Curated repository PoCs
GitHubCVE-2025-32814Curated repository PoCby RhinoSecurityLabsStars: 905Not analyzed2 files
Nuclei templates
1ProjectDiscoveryCRITICALNetMRI Unauthenticated SQL Injection via skipjackUsernameCVSS 9.8
An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.
Impact
Unauthenticated attackers can extract sensitive data including encrypted passwords through SQL injection in the skipjackUsername parameter, potentially leading to complete system compromise.
Remediation
Upgrade to Infoblox NetMRI version 7.6.1 or later that properly sanitizes SQL input parameters.
Source: ProjectDiscovery