N-able N-central是加拿大N-able公司的一个 RMM 平台。为成熟的 MSP 和 IT 专业人员提供了大规模管理、自动化和编排功能。 N-able N-central 2025.4之前版本存在安全漏洞,该漏洞源于为未验证用户生成会话ID。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | N-central < 2025.4 can generate sessionIDs for unauthenticated users This issue affects N-central: before 2025.4. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-9316.yaml | POC Details |
| 2 | Proof of concept exploit for N-able N-central to chain CVE-2025-9316 and CVE-2025-11700 to read files | https://github.com/horizon3ai/n-able_n-central_xxe_file_read | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-11366 | N-central Authentication bypass via path traversal | |
| CVE-2025-11700 | N-central Multiple XXE Injection Vulnerabilities | |
| CVE-2025-11367 | N-central windows software probe Remote Code Execution |
No comments yet