CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2025-8875

CVSS 9.4v4.0pub. 2025-08-14upd. 2025-10-27

Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.

🤖 AI Analysis
How it works

The vulnerability mechanism is based on improper handling of the data deserialization process — the application processes crafted, untrusted data without appropriate verification of its content. An authenticated user (PR:L level privileges required) can upload a malicious payload that is executed on the server-side during deserialization. The attack vector is network-based, and its exploitation does not require user interaction or special technical conditions.

Impact

Successful exploitation of the vulnerability allows an attacker to execute arbitrary code on the server (RCE), which combined with high impact on confidentiality, integrity, and availability of both the attacked system and related systems (SC:H/SI:H/SA:H), can lead to complete compromise of the infrastructure managed by N-Central.

Mitigation & patch

N-Able N-Central must be immediately updated to version 2025.3.1 or later. The patch is available in accordance with the vendor's announcement published on August 13, 2025 at: https://status.n-able.com/2025/08/13/announcing-the-ga-of-n-central-2025-3-1/. Due to active exploitation, the update should be treated as a priority.

Who is affected

N-Able N-Central in all versions preceding 2025.3.1

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • N Able N Central

    APP
    N-Able
    < 2025.3.1

CISA KEV — detailsi

Vendori
N-able
Producti
N-Central
Added to KEVi
August 13, 2025
Remediation deadline (US Federal)i
August 20, 2025(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 20 sierpnia 2025
Tags
Deserialization
CWE
References

Related vulnerabilities

CVE-2025-8876CRITICAL9.4⚠ KEVPL ✓same product

OS Command Injection w N-able N-central (przed wersją 2025.3.1)

CVE-2025-11366CRITICAL9.4PL ✓same product

Authentication bypass via path traversal w N-Able N-Central

CVE-2025-11367CRITICAL10.0PL ✓same product

RCE przez deserialization w N-Able N-Central Software Probe

CVE-2024-28200CRITICAL9.1PL ✓same product

Authentication Bypass interfejsu użytkownika w N-Able N-Central

CVE-2024-5322CRITICAL9.1PL ✓same product

Authentication Bypass w N-Able N-Central poprzez session rebinding (Entra SSO)