Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.
The vulnerability mechanism is based on improper handling of the data deserialization process — the application processes crafted, untrusted data without appropriate verification of its content. An authenticated user (PR:L level privileges required) can upload a malicious payload that is executed on the server-side during deserialization. The attack vector is network-based, and its exploitation does not require user interaction or special technical conditions.
Successful exploitation of the vulnerability allows an attacker to execute arbitrary code on the server (RCE), which combined with high impact on confidentiality, integrity, and availability of both the attacked system and related systems (SC:H/SI:H/SA:H), can lead to complete compromise of the infrastructure managed by N-Central.
N-Able N-Central must be immediately updated to version 2025.3.1 or later. The patch is available in accordance with the vendor's announcement published on August 13, 2025 at: https://status.n-able.com/2025/08/13/announcing-the-ga-of-n-central-2025-3-1/. Due to active exploitation, the update should be treated as a priority.
N-Able N-Central in all versions preceding 2025.3.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XN Able N Central
APPN-Able< 2025.3.1
CISA KEV — detailsi
- Vendori
- N-able
- Producti
- N-Central
- Added to KEVi
- August 13, 2025
- Remediation deadline (US Federal)i
- August 20, 2025(overdue)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution.
Related vulnerabilities
OS Command Injection w N-able N-central (przed wersją 2025.3.1)
Authentication bypass via path traversal w N-Able N-Central
RCE przez deserialization w N-Able N-Central Software Probe
Authentication Bypass interfejsu użytkownika w N-Able N-Central
Authentication Bypass w N-Able N-Central poprzez session rebinding (Entra SSO)