Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.
The vulnerability results from improper input validation (CWE-20), which leads to the possibility of system command injection (CWE-78, command injection). An authenticated network user can supply crafted input data, which is then interpreted and executed as operating system commands on the server. The attack does not require user interaction or special configuration conditions; possession of an account with basic privileges is sufficient.
An attacker can gain full control over the server operating system, including reading, modifying, and deleting data, as well as potential lateral movement within the network managed by N-central. Due to high impact ratings on the confidentiality, integrity, and availability of both the local system and related systems, the consequences of compromise are critical.
N-able N-central should be immediately updated to version 2025.3.1 or later, in accordance with the vendor's official announcement available at: https://status.n-able.com/2025/08/13/announcing-the-ga-of-n-central-2025-3-1/
N-able N-central in all versions before 2025.3.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XN Able N Central
APPN-Able< 2025.3.1
CISA KEV — detailsi
- Vendori
- N-able
- Producti
- N-Central
- Added to KEVi
- August 13, 2025
- Remediation deadline (US Federal)i
- August 20, 2025(overdue)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
N-able N-Central contains a command injection vulnerability via improper sanitization of user input.
Related vulnerabilities
Deserializacja niezaufanych danych w N-Able N-Central umożliwia RCE
Authentication bypass via path traversal w N-Able N-Central
RCE przez deserialization w N-Able N-Central Software Probe
Authentication Bypass interfejsu użytkownika w N-Able N-Central
Authentication Bypass w N-Able N-Central poprzez session rebinding (Entra SSO)