CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-11366

CVSS 9.4v4.0pub. 2025-11-12upd. 2025-11-14

N-central < 2025.4 is vulnerable to authentication bypass via path traversal

🤖 AI Analysis
How it works

The vulnerability classified as CWE-22 (path traversal) allows an attacker to manipulate network request paths in such a way as to bypass the application's authentication mechanisms. An attacker with only a low-privilege account (PR:L) can send a specially crafted HTTP request containing path traversal sequences that result in access to protected resources without the required authorization. The attack vector is network-based, without the need for physical access or user interaction on the victim's side.

Impact

Successful exploitation of this vulnerability allows an attacker to bypass authentication mechanisms and gain unauthorized access to the N-Central system, which according to the CVSS vector involves a high impact on the confidentiality, integrity, and availability of both the system itself and related systems.

Mitigation & patch

N-Able N-Central must be immediately updated to version 2025.4 or later. Detailed information is available in the official security bulletin from the vendor at the address indicated in the references.

Who is affected

N-Able N-Central in versions prior to 2025.4

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • N Able N Central

    APP
    N-Able
    < 2025.4
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Path TraversalAuth Bypass
CWE
References

Related vulnerabilities

CVE-2025-8875CRITICAL9.4⚠ KEVPL ✓same product

Deserializacja niezaufanych danych w N-Able N-Central umożliwia RCE

CVE-2025-8876CRITICAL9.4⚠ KEVPL ✓same product

OS Command Injection w N-able N-central (przed wersją 2025.3.1)

CVE-2025-11367CRITICAL10.0PL ✓same product

RCE przez deserialization w N-Able N-Central Software Probe

CVE-2024-28200CRITICAL9.1PL ✓same product

Authentication Bypass interfejsu użytkownika w N-Able N-Central

CVE-2024-5322CRITICAL9.1PL ✓same product

Authentication Bypass w N-Able N-Central poprzez session rebinding (Entra SSO)