CVE-2025-22217 - CVE House
Back to Database
Status published High CVE-2025-22217

Avi Load Balancer contains an unauthenticated blind SQL Injection vulnerability...

Vulnerability Description

Avi Load Balancer contains an unauthenticated blind SQL Injection vulnerability which was privately reported to VMware. Patches are available to remediate this vulnerability in affected VMware products.  A malicious user with network access may be able to use specially crafted SQL queries to gain database access.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-22217

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

VMware AVI Load Balancer
Vulnerable Versions:
VMware AVI Load Balancer 30.1.x and VMware AVI Load Balancer 30.2.x and

Timeline

Official Publish: January 28th, 2025
Last Modified: February 26th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Weaknesses (CWE)