CVE-2025-9316 describes an authentication bypass vulnerability in N-central versions prior to 2025.4, where the system can generate session IDs for unauthenticated users. This medium-severity vulnerability (CVSS 6.9) has a low attack complexity and requires no user interaction, allowing remote attackers to potentially gain unauthorized access. While not confirmed as actively exploited, public exploit modules exist for Metasploit and Nuclei, and the vulnerability has garnered significant community discussion, indicating a high potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2025.4CPE match | cpe:2.3:a:n-able:n-central:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.