CVE-2025-32815
MEDIUMNuclei
infoblox netmri Improper Authentication
Record summary
CVE-2025-32815 has a selected CVSS score of 6.5 (medium); EIP currently links 1 curated repository PoC and 1 Nuclei template.
Description
An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 21, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 22, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
netmriBrowse infoblox / netmri | VulnCheck | Version data not supplied | |
Proofs of concept
1Curated repository PoCs
GitHubCVE-2025-32815Curated repository PoCby RhinoSecurityLabsStars: 905Not analyzed2 files
Nuclei templates
1ProjectDiscoveryMEDIUMNetMRI < 7.6.1 - Authentication Bypass via Hardcoded CredentialsCVSS 6.5
An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.
Impact
Attackers can bypass authentication using hardcoded credentials to access administrative functions and read sensitive system files including /etc/shadow.
Remediation
Upgrade to Infoblox NetMRI version 7.6.1 or later and change all default credentials immediately.
WeaknessesCWE-287
Authorsiamnoooob, pdresearch
Template tagscvecve2025auth-bypassnetmrihardcodedinfobloxvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
CPE: cpe:2.3:a:infoblox:netmri:*:*:*:*:*:*:*:*
FOFA: icon_hash="-319724102"
https://rhinosecuritylabs.com/research/infoblox-multiple-cves/ https://nvd.nist.gov/vuln/detail/CVE-2025-32815
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-32815 support.infoblox.com
https://support.infoblox.com/s/article/Infoblox-NetMRI-is-vulnerable-to-CVE-2025-32815