SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Protect Your Systems: VMware Avi Load Balancer Hit by High-Risk SQL Injection Flaw

Protect Your Systems: VMware Avi Load Balancer Hit by High-Risk SQL Injection Flaw

Introduction

Jan 30, 2025By Rahul Gande4 min read

Introduction

Cybersecurity is a top priority for businesses worldwide, and vulnerabilities in critical software can have dire consequences. A recent high-severity flaw discovered in VMware Avi Load Balancer has raised alarms for IT teams and security professionals. This vulnerability tracked as CVE-2025-22217, could potentially allow cybercriminals to gain unauthorized access to sensitive database information, posing a significant risk to organizations relying on VMware’s load-balancing technology.

In this blog, we will delve into the details of this vulnerability, the affected versions of VMware Avi Load Balancer, and the steps you should take to secure your systems.

What is CVE-2025-22217?

The flaw is an unauthenticated blind SQL injection vulnerability, with a CVSS score of 8.6, making it a critical security concern. The vulnerability allows an attacker with network access to craft and execute specially designed SQL queries. These queries could be used to manipulate or retrieve sensitive data from the associated database without authentication.

An unauthenticated SQL injection means that attackers do not need to log in to the system to exploit this weakness, making it even more dangerous. Once they gain access, they gain complete control over the database, leading to data breaches, service disruptions, and other malicious activities.

Affected Versions of VMware Avi Load Balancer

This vulnerability affects the following versions of VMware Avi Load Balancer:

  • VMware Avi Load Balancer 30.1.1 (Fixed in 30.1.2-2p2)
  • VMware Avi Load Balancer 30.1.2 (Fixed in 30.1.2-2p2)
  • VMware Avi Load Balancer 30.2.1 (Fixed in 30.2.1-2p5)
  • VMware Avi Load Balancer 30.2.2 (Fixed in 30.2.2-2p2)

Broadcom, which owns VMware, confirmed that this vulnerability does not impact versions 22.x and 21.x, so users on those versions do not need to worry about the flaw.

How Does the Vulnerability Work?

The vulnerability allows attackers to send malicious SQL queries to the load balancer, which processes the request without proper validation. In a blind SQL injection attack, attackers don’t receive direct output from the system, but they can still infer information about the underlying database by manipulating queries. This attack is stealthy and difficult to detect, as it does not generate apparent errors or warnings that would alert administrators.

An attacker who successfully exploits this flaw could gain database access and potentially manipulate or leak sensitive information, compromise system integrity, or escalate privileges, making it a serious threat to any organization using affected versions of VMware Avi Load Balancer.

What Are the Fixes?

To mitigate the risks posed by CVE-2025-22217, VMware has released patches in the following updated versions:

  • 30.1.2 or later
  • 30.2.1-2p5 or later
  • 30.2.2-2p2 or later

Broadcom also recommended that customers using version 30.1.1 upgrade to version 30.1.2 or later before applying the patch to ensure adequate protection.

No Workarounds Available

Unfortunately, no workarounds are available to address the vulnerability. As a result, the only viable option is for users to upgrade to the patched versions to ensure their systems remain secure.

Conclusion

The discovery of CVE-2025-22217 serves as a reminder of the ongoing need for vigilance in cybersecurity. Even widely used technologies like VMware’s Avi Load Balancer can harbour critical vulnerabilities that, if exploited, can have serious consequences for organizations and their data.

Security professionals and IT teams should prioritize applying patches and updates promptly. Given the severity of this flaw, there is no time to waste in securing systems against potential attacks. Organizations can significantly reduce their exposure to this and similar vulnerabilities by staying informed and acting quickly.

Patch Dangerous Vulns Instantly with SanerNow

SecPod SanerNow is the Patch Management tool you need to detect and patch dangerous risks and remediate your attack surface. SanerNow automatically scans for risks, downloads and deploys patches accordingly. Further, SanerNow supports all major OSs and 550+ third-party applications.

Schedule a demo and keep your systems updated and secure with SanerNow: Schedule here

Featured Posts

Open Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras
Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

CVE Research

Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

A single operator compromised 14,530+ Dahua cameras across Ukraine and Russia in 35 days, chaining credential brute-force, a CVE-2021-33044/33045 authentication bypass, and P2P relay abuse to plant a persistent backdoor and harvest transferable admin access.

Aug 21, 2026

Open Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF
Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE Research

Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE-2026-19478 is a critical code injection vulnerability in GitLab CE/EE that allows an unauthenticated attacker to modify or delete public projects and user data by abusing a GraphQL directive. A second high-severity issue, CVE-2026-19650, involves cross-site request forgery in the GraphQL multiplex query handler. This article examines how the critical vulnerability works, the availability of a public proof-of-concept, the potential impact on self-managed instances, the affected versions, and the security updates released to remediate both issues.

Aug 19, 2026

Open No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners
No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

CVE Research

No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

Aug 19, 2026

Open Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies
Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

CVE Research

Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

Aug 19, 2026