CVE-2025-8875 is a critical Deserialization of Untrusted Data vulnerability affecting N-able N-central versions prior to 2025.3.1. This flaw allows for Local Execution of Code, posing a significant risk to affected systems. Rated with a CVSS score of 7.8 (HIGH), the vulnerability has a low attack complexity and requires local access, but successful exploitation grants high confidentiality, integrity, and availability impacts. Its FAUCET Risk Score is 99/100, indicating extreme severity. Crucially, this CVE is actively exploited in the wild, as confirmed by its presence in the KEV catalog and extensive media coverage. While no public Metasploit or ExploitDB modules exist, there is significant community discussion and a detection script available on GitHub, highlighting its active threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2025.3.1CPE match | cpe:2.3:a:n-able:n-central:*:*:*:*:*:*:*:* | ||
< 2025.3.1CPE matchmatch criteria | cpe:2.3:a:n-able:n-central:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.