PT-2026-7860 · Infoblox · Infoblox Nios
Published
2026-02-12
·
Updated
2026-02-19
·
CVE-2025-61880
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Infoblox NIOS versions through 9.0.7
Description
The software contains an insecure deserialization issue that can lead to remote code execution. The issue affects devices worldwide, but the number of potentially affected devices is not specified. The vulnerability involves the deserialization process, which, if exploited, could allow an attacker to execute arbitrary code on the system. No specific API endpoints or vulnerable parameters were mentioned.
Recommendations
Versions prior to 9.0.7 are affected.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Infoblox Nios