ZeroHour

CVE-2025-11700

large

XXE Information Disclosure in N-able N-central Before 2025.4

CVSS 4.0
8.4 high
EPSS
31%p98
Published
()
Modified
AI analysis

N-able N-central contains multiple XML External Entity (XXE) injection flaws (CWE-611), where the application's XML parser processes attacker-supplied XML containing external entity references. The CVSS 4.0 vector indicates the attack is network-based and requires only low privileges (an authenticated, low-privileged account), with no user interaction required. A successful attack discloses sensitive information: an attacker can have the XML parser read local files on the N-central server — potentially exposing stored credentials or configuration data — and the vector's high impact to subsequent systems suggests disclosed secrets could reach other connected systems; there is no integrity or availability impact. All N-central deployments running versions prior to 2025.4 are affected, and N-central is primarily operated by managed service providers as a central RMM management server overseeing large fleets of customer endpoints. No public proof-of-concept or confirmed in-the-wild exploitation is known, but the EPSS score of 30.7% (98th percentile) signals a high predicted probability of exploitation within the next 30 days.

What to do: Upgrade N-central to version 2025.4 or later, as no workarounds are documented for the XXE issues. Until patched, restrict network access to the N-central server's web and API interfaces to trusted management networks, audit which low-privileged accounts can submit XML-accepting requests, and monitor logs for anomalous XML parsing activity. Because the flaw can disclose files that may contain stored credentials, review the server's local credential stores for exposure.

Affected
N-able N-centralAll versions prior to 2025.4
Estimated exposure
large≈10,000–50,000 N-central management servers (MSP on-premises and hosted deployments, each managing hundreds to thousands of endpoints) — N-central is one of the major RMM platforms deployed by MSPs, and public internet scans historically show tens of thousands of exposed N-central management servers, so the vulnerable install base is estimated in that order of magnitude.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure

Vendors
n-able
Products
n-central
Weakness
CWE-611
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.