Record summary

CVE-2025-32815 has a selected CVSS score of 6.5 (medium); EIP currently links 1 curated repository PoC and 1 Nuclei template.

Description

An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jul 21, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Curated repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 22, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Curated repository PoCs

GitHubCVE-2025-32815Curated repository PoCby RhinoSecurityLabsStars: 905Not analyzed2 files

Python · 26.0 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMNetMRI < 7.6.1 - Authentication Bypass via Hardcoded CredentialsCVSS 6.5

An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.

Impact

Attackers can bypass authentication using hardcoded credentials to access administrative functions and read sensitive system files including /etc/shadow.

Remediation

Upgrade to Infoblox NetMRI version 7.6.1 or later and change all default credentials immediately.

WeaknessesCWE-287
Authorsiamnoooob, pdresearch
Template tagscvecve2025auth-bypassnetmrihardcodedinfobloxvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
CPE: cpe:2.3:a:infoblox:netmri:*:*:*:*:*:*:*:*
FOFA: icon_hash="-319724102"

Source: ProjectDiscovery

References

2