CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2025-8876

CVSS 9.4v4.0pub. 2025-08-14upd. 2025-10-27

Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.

🤖 AI Analysis
How it works

The vulnerability results from improper input validation (CWE-20), which leads to the possibility of system command injection (CWE-78, command injection). An authenticated network user can supply crafted input data, which is then interpreted and executed as operating system commands on the server. The attack does not require user interaction or special configuration conditions; possession of an account with basic privileges is sufficient.

Impact

An attacker can gain full control over the server operating system, including reading, modifying, and deleting data, as well as potential lateral movement within the network managed by N-central. Due to high impact ratings on the confidentiality, integrity, and availability of both the local system and related systems, the consequences of compromise are critical.

Mitigation & patch

N-able N-central should be immediately updated to version 2025.3.1 or later, in accordance with the vendor's official announcement available at: https://status.n-able.com/2025/08/13/announcing-the-ga-of-n-central-2025-3-1/

Who is affected

N-able N-central in all versions before 2025.3.1

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • N Able N Central

    APP
    N-Able
    < 2025.3.1

CISA KEV — detailsi

Vendori
N-able
Producti
N-Central
Added to KEVi
August 13, 2025
Remediation deadline (US Federal)i
August 20, 2025(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

N-able N-Central contains a command injection vulnerability via improper sanitization of user input.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 20 sierpnia 2025
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2025-8875CRITICAL9.4⚠ KEVPL ✓same product

Deserializacja niezaufanych danych w N-Able N-Central umożliwia RCE

CVE-2025-11366CRITICAL9.4PL ✓same product

Authentication bypass via path traversal w N-Able N-Central

CVE-2025-11367CRITICAL10.0PL ✓same product

RCE przez deserialization w N-Able N-Central Software Probe

CVE-2024-28200CRITICAL9.1PL ✓same product

Authentication Bypass interfejsu użytkownika w N-Able N-Central

CVE-2024-5322CRITICAL9.1PL ✓same product

Authentication Bypass w N-Able N-Central poprzez session rebinding (Entra SSO)