← Vulnerability feed

Vulnerability record · CVE-2021-41080 · published 11 November 2021

CVE-2021-41080: Zohocorp manageengine network configuration manager sql injection vulnerability

Zohocorp · Manageengine Network Configuration Manager

Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a hardware details search.

9.8 CVSS 3.1 Critical EPSS 4.6% · top 8.7% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
4.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a hardware details search.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-41080 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-43319Zohocorp manageengine network configuration manager command injection vulnerabilityZoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validation in the Ping functionality.EPSS 21%9.8CVE-2021-41081ManageEngine Network Configuration Manager SQL injection in configuration searchZoho ManageEngine Network Configuration Manager before build 125465 contains a SQL injection flaw in a configuration search function. Because the que…EPSS 64%analysed8.8CVE-2023-29505Zohocorp manageengine network configuration manager origin validation error vulnerabilityAn issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.EPSS 1.1%8.8CVE-2022-38772ManageEngine OpManager and related products NMAP feature RCE via authenticated DB changesMultiple Zoho ManageEngine products (OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, OpUtils) before speci…EPSS 78%analysed8.8CVE-2022-37024Zoho ManageEngine ITOM products allow authenticated database changes leading to RCEMultiple Zoho ManageEngine products (OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, OpUtils, Firewall Ana…EPSS 79%analysed8.6CVE-2023-47211ManageEngine OpManager uploadMib path traversal allows arbitrary file creationThe uploadMib function in ManageEngine OpManager 12.7.258 does not properly validate paths, so a crafted HTTP request carrying a malicious MIB file c…EPSS 47%analysed8.2CVE-2022-35404Zohocorp manageengine opmanager improper input validation vulnerabilityManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a serv…EPSS 2.9%7.8CVE-2019-12133Zohocorp manageengine analytics plus uncontrolled search path element vulnerabilityMultiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory a…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2021-41080), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.