ZeroHour

CVE-2025-9316

large

Unauthenticated Session ID Generation Flaw in N-able N-central

CVSS 4.0
6.9 medium
EPSS
36%p98
Published
()
Modified
AI analysis

N-able N-central versions before 2025.4 contain a flaw (CWE-1284, improper validation of an input quantity) that allows the server to generate session IDs for unauthenticated users. An attacker can trigger this remotely over the network with no privileges or user interaction required. Per the CVSS 4.0 score of 6.9 (medium), the impact is limited to confidentiality (VC:L), meaning an attacker can obtain or create session identifiers without authenticating, potentially enabling session hijacking or unauthorized access to the N-central console. Any organization running N-central prior to 2025.4 — primarily managed service providers (MSPs) using the RMM platform — is affected. No public proof-of-concept exists and the flaw is not in CISA's KEV catalog, but the EPSS score of 36.3% (98th percentile) indicates an elevated probability of exploitation in the next 30 days.

What to do: Upgrade N-central to version 2025.4 or later. Until patched, restrict internet exposure of N-central consoles via VPN or firewall allowlisting, review active sessions for anomalies, and monitor the vendor's security advisories given the elevated EPSS likelihood.

Affected
N-able N-centralbefore 2025.4
Estimated exposure
largetens of thousands of N-central server deployments worldwide (thousands typically internet-exposed) — N-central is a flagship RMM platform used by thousands of MSPs, typically deployed as one or a few internet-accessible management servers per MSP, implying an order of magnitude of tens of thousands of installations.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

N-central < 2025.4 can generate sessionIDs for unauthenticated users This issue affects N-central: before 2025.4.

Weakness
CWE-1284
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news