CVE-2025-61880 Details
Description
In Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution.
A vulnerability exists in Infoblox NIOS versions through 9.0.7, where insecure deserialization can lead to remote code execution. This issue allows unauthenticated attackers to execute arbitrary code or files on the system.
Users can upgrade to Infoblox NIOS version 9.0.8, which includes the fix for this vulnerability. For NIOS versions 8.5.2, 8.6.5, and 9.0.1 through 9.0.7, a version-specific hotfix is available. Instructions for applying this hotfix can be found in the Infoblox support article
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://infoblox.com | [email protected] | Product |
| https://support.infoblox.com/s/article/CVE-2025-61879-and-CVE-2025-61880 | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| infoblox nios | >= 8.6.0, <= 8.6.5 8.5.2 9.0.1 9.0.2 9.0.3 9.0.4 9.0.5 9.0.6 9.0.7 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 19, 2026 | Initial Analysis | [email protected] |
| Feb 12, 2026 | CVE Modified | CISA-ADP |
| Feb 12, 2026 | New CVE Received | [email protected] |