N-able N-central是加拿大N-able公司的一个 RMM 平台。为成熟的 MSP 和 IT 专业人员提供了大规模管理、自动化和编排功能。 N-able N-central 2025.4之前版本存在安全漏洞,该漏洞源于XML外部实体注入,可能导致信息泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | N-central versions < 2025.4 are vulnerable to an XML External Entities injection leading to information disclosure. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-11700.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-11366 | N-central Authentication bypass via path traversal | |
| CVE-2025-11367 | N-central windows software probe Remote Code Execution | |
| CVE-2025-9316 | N-central unauthenticated sessionID generation |
No comments yet