← Vulnerability feed

Vulnerability record · CVE-2021-41081 · published 11 November 2021

CVE-2021-41081: ManageEngine Network Configuration Manager SQL injection in configuration search

Zohocorp · Manageengine Network Configuration Manager

Zoho ManageEngine Network Configuration Manager before build 125465 contains a SQL injection flaw in a configuration search function. Because the query is built from unvalidated input, an unauthenticated remote attacker can inject SQL and read or alter the underlying database. The vendor has released a fixed build, so exposure is limited to unpatched installations.

9.8 CVSS 3.1 Critical EPSS 64% · top 0.8% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a configuration search.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityA network-reachable, unauthenticated SQL injection with CVSS 9.8 and very high EPSS makes this an urgent patch target despite no KEV listing.

What it is

Zoho ManageEngine Network Configuration Manager before build 125465 contains a SQL injection flaw in a configuration search function. Because the query is built from unvalidated input, an unauthenticated remote attacker can inject SQL and read or alter the underlying database. The vendor has released a fixed build, so exposure is limited to unpatched installations.

Impact

An attacker can execute arbitrary SQL against the application database, gaining read and write access to stored configuration and credential data and potentially full compromise of the affected system. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

The flaw is reachable over the network through the configuration search feature, with no authentication and no user interaction required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Any internet- or intranet-exposed instance of the affected product is a candidate target.

Exploitation

The record is not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at roughly 0.64 (99th percentile), indicating a strong likelihood of exploitation activity. The only references are vendor advisories, so no public exploit code is confirmed by this record.

What to do

  • Upgrade ManageEngine Network Configuration Manager to build 125465 or later as the primary fix.
  • If immediate patching is not possible, restrict network access to the application to trusted management networks only.
  • Place the product behind a reverse proxy or WAF with SQL injection filtering as a temporary compensating control.
  • Audit database accounts used by the application and remove unnecessary privileges to limit injection impact.
  • Review logs for suspicious search requests and rotate any credentials stored in the product.

Detection

  • Monitor web and application logs for configuration search requests containing SQL metacharacters such as quotes, UNION, or comment sequences.
  • Alert on database errors or unexpected query patterns returned by the application.
  • Baseline normal search parameters and flag anomalous or unusually long query strings from single source IPs.
  • Watch for outbound database or file access activity from the application host that deviates from normal behavior.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-41081 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-43319Zohocorp manageengine network configuration manager command injection vulnerabilityZoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validation in the Ping functionality.EPSS 21%9.8CVE-2021-41080Zohocorp manageengine network configuration manager sql injection vulnerabilityZoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a hardware details search.EPSS 4.6%8.8CVE-2023-29505Zohocorp manageengine network configuration manager origin validation error vulnerabilityAn issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.EPSS 1.1%8.8CVE-2022-38772ManageEngine OpManager and related products NMAP feature RCE via authenticated DB changesMultiple Zoho ManageEngine products (OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, OpUtils) before speci…EPSS 78%analysed8.8CVE-2022-37024Zoho ManageEngine ITOM products allow authenticated database changes leading to RCEMultiple Zoho ManageEngine products (OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, OpUtils, Firewall Ana…EPSS 79%analysed8.6CVE-2023-47211ManageEngine OpManager uploadMib path traversal allows arbitrary file creationThe uploadMib function in ManageEngine OpManager 12.7.258 does not properly validate paths, so a crafted HTTP request carrying a malicious MIB file c…EPSS 47%analysed8.2CVE-2022-35404Zohocorp manageengine opmanager improper input validation vulnerabilityManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a serv…EPSS 2.9%7.8CVE-2019-12133Zohocorp manageengine analytics plus uncontrolled search path element vulnerabilityMultiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory a…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2021-41081), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.