Rhino Security Labs

Technical Blog

Multiple CVEs in Infoblox NetMRI: RCE, Auth Bypass, SQLi, and File Read Vulnerabilities  

David Yesland
June 4, 2025

While performing research on Infoblox’s NetMRI network automation and configuration management solution, we discovered 6 vulnerabilities in version 7.5.4.104695 of the NetMRI virtual appliance. These ranged from unauthenticated…

CVE-2025-26147: Authenticated RCE In Denodo Scheduler 

New Pacu Module:
Secret Enumeration in Elastic Beanstalk

CVE-2024-55963: Unauthenticated RCE in Default-Install of Appsmith

Whit Taylor

While reviewing the Appsmith Enterprise platform, Rhino Security Labs uncovered a series of critical vulnerabilities affecting default installations of the product. Most severe among them is CVE-2024-55963, which allows unauthenticated…