CVE-2025-11700 is a high-severity XML External Entities (XXE) injection vulnerability affecting N-able N-central versions prior to 2025.4, allowing for information disclosure. With a CVSS score of 7.5 (High), it can be exploited remotely without authentication, posing a significant risk of data compromise. While not yet in CISA's KEV catalog, public exploit modules for Metasploit and Nuclei exist, and there is substantial community discussion, indicating a high likelihood of exploitation. Organizations using affected N-central versions should prioritize patching to mitigate this critical threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2025.4CPE matchmatch criteria | cpe:2.3:a:n-able:n-central:*:*:*:*:*:*:*:* | ||
>= 0, < 2025.4CPE match | cpe:2.3:a:n-able:n-central:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.