Record summary

CVE-2025-32814 has a selected CVSS score of 9.8 (critical); EIP currently links 1 curated repository PoC and 1 Nuclei template.

Description

An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jul 22, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Curated repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 22, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Curated repository PoCs

GitHubCVE-2025-32814Curated repository PoCby RhinoSecurityLabsStars: 905Not analyzed2 files

Python · 21.6 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALNetMRI Unauthenticated SQL Injection via skipjackUsernameCVSS 9.8

An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.

Impact

Unauthenticated attackers can extract sensitive data including encrypted passwords through SQL injection in the skipjackUsername parameter, potentially leading to complete system compromise.

Remediation

Upgrade to Infoblox NetMRI version 7.6.1 or later that properly sanitizes SQL input parameters.

WeaknessesCWE-89
Authorsiamnoooob, pdresearch
Template tagscvecve2025sqliunauthnetmrirailserror-basedvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:infoblox:netmri:*:*:*:*:*:*:*:*
FOFA: icon_hash="-319724102"

Source: ProjectDiscovery

References

2