CVE-2025-11700
largeXXE Information Disclosure in N-able N-central Before 2025.4
N-able N-central contains multiple XML External Entity (XXE) injection flaws (CWE-611), where the application's XML parser processes attacker-supplied XML containing external entity references. The CVSS 4.0 vector indicates the attack is network-based and requires only low privileges (an authenticated, low-privileged account), with no user interaction required. A successful attack discloses sensitive information: an attacker can have the XML parser read local files on the N-central server — potentially exposing stored credentials or configuration data — and the vector's high impact to subsequent systems suggests disclosed secrets could reach other connected systems; there is no integrity or availability impact. All N-central deployments running versions prior to 2025.4 are affected, and N-central is primarily operated by managed service providers as a central RMM management server overseeing large fleets of customer endpoints. No public proof-of-concept or confirmed in-the-wild exploitation is known, but the EPSS score of 30.7% (98th percentile) signals a high predicted probability of exploitation within the next 30 days.
What to do: Upgrade N-central to version 2025.4 or later, as no workarounds are documented for the XXE issues. Until patched, restrict network access to the N-central server's web and API interfaces to trusted management networks, audit which low-privileged accounts can submit XML-accepting requests, and monitor logs for anomalous XML parsing activity. Because the flaw can disclose files that may contain stored credentials, review the server's local credential stores for exposure.
| N-able N-central | All versions prior to 2025.4 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure
- Vendors
- n-able
- Products
- n-central
- Weakness
- CWE-611
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.