CVE-2025-11700

N-central versions < 2025.4 are vulnerable to an XML External Entities injection leading to information disclosure
Configurations

Configuration 1 (hide)

cpe:2.3:a:n-able:n-central:*:*:*:*:*:*:*:*

History

14 Nov 2025, 19:30

Type Values Removed Values Added
CPE cpe:2.3:a:n-able:n-central:*:*:*:*:*:*:*:*
First Time N-able n-central
N-able
References () https://me.n-able.com/s/security-advisory/aArVy0000000rabKAA/cve202511700-ncentral-importservicefromfile-xxe-injection - () https://me.n-able.com/s/security-advisory/aArVy0000000rabKAA/cve202511700-ncentral-importservicefromfile-xxe-injection - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

12 Nov 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-12 16:15

Updated : 2025-11-14 19:30


NVD link : CVE-2025-11700

Mitre link : CVE-2025-11700

CVE.ORG link : CVE-2025-11700


JSON object : View

Products Affected

n-able

  • n-central
CWE
CWE-611

Improper Restriction of XML External Entity Reference