PT-2026-7860 · Infoblox · Infoblox Nios
Publicado
2026-02-12
·
Atualizado
2026-02-19
·
CVE-2025-61880
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Infoblox NIOS versions through 9.0.7
Description
The software contains an insecure deserialization issue that can lead to remote code execution. The issue affects devices worldwide, but the number of potentially affected devices is not specified. The vulnerability involves the deserialization process, which, if exploited, could allow an attacker to execute arbitrary code on the system. No specific API endpoints or vulnerable parameters were mentioned.
Recommendations
Versions prior to 9.0.7 are affected.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Deserialization of Untrusted Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Infoblox Nios