Infoblox maintains a focused portfolio of DNS, DHCP, and network management appliances that serve as critical infrastructure for IP address management and domain name resolution across enterprises, positioning them as high-value targets despite their narrow product scope. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a marked tendency toward public exploit availability, reflecting the security-sensitive role these appliances play in network operations. The exposure recurs across products such as NetMRI, NIOS, and BloxOne Endpoint through weakness classes including improper access control, cross-site scripting, improper authentication, and OS command injection, which are characteristic of web-facing management interfaces and input-handling code in appliance firmware. Defenders should prioritize visibility and segmentation around these appliances, as their internet-accessible management functions and upstream network position amplify the impact of successful compromise; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Infoblox over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-32814CRITICAL An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur. | May 22, 2025 | 9.8 | 63 | NO | YES |
CVE-2025-32813HIGH An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur. | May 22, 2025 | 7.2 | 58 | NO | YES |
CVE-2025-32815MEDIUM An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur. | May 22, 2025 | 6.5 | 55 | NO | YES |
CVE-2004-0460HIGH Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause a denial of service (server crash) and p | Aug 6, 2004 | 10.0 | 48 | NO | NO |
CVE-2014-3418HIGH config/userAdmin/login.tdf in Infoblox NetMRI before 6.8.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the skipjackUsername parameter. | Jul 15, 2014 | 10.0 | 38 | NO | YES |
CVE-2004-0461HIGH The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C include files that define vsnprintf t | Aug 6, 2004 | 10.0 | 38 | NO | NO |
CVE-2025-61880HIGH In Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution. | Feb 12, 2026 | 8.8 | 28 | NO | NO |
CVE-2024-36047CRITICAL Infoblox NIOS through 8.6.4 and 9.x through 9.0.3 has Improper Input Validation. | Feb 27, 2025 | 9.8 | 28 | NO | NO |
CVE-2024-52874HIGH In Infoblox NETMRI before 7.6.1, authenticated users can perform SQL injection attacks. | May 22, 2025 | 8.8 | 26 | NO | NO |
CVE-2024-37566CRITICAL Infoblox NIOS through 8.6.4 has Improper Authentication for Grids. | Feb 27, 2025 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Infoblox.
Media articles that mention a CVE ID that affects a product developed by Infoblox — matched by CVE ID, not by vendor name.