CVE-2025-11700

N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure
Configurations

Configuration 1 (hide)

cpe:2.3:a:n-able:n-central:*:*:*:*:*:*:*:*

History

15 Dec 2025, 15:15

Type Values Removed Values Added
References
  • {'url': 'https://me.n-able.com/s/security-advisory/aArVy0000000rabKAA/cve202511700-ncentral-importservicefromfile-xxe-injection', 'tags': ['Vendor Advisory'], 'source': 'a5532a13-c4dd-4202-bef1-e0b8f2f8d12b'}
  • () https://me.n-able.com/s/security-advisory/aArVy0000000rabKAA -
Summary (en) N-central versions < 2025.4 are vulnerable to an XML External Entities injection leading to information disclosure (en) N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure

14 Nov 2025, 19:30

Type Values Removed Values Added
CPE cpe:2.3:a:n-able:n-central:*:*:*:*:*:*:*:*
First Time N-able n-central
N-able
References () https://me.n-able.com/s/security-advisory/aArVy0000000rabKAA/cve202511700-ncentral-importservicefromfile-xxe-injection - () https://me.n-able.com/s/security-advisory/aArVy0000000rabKAA/cve202511700-ncentral-importservicefromfile-xxe-injection - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

12 Nov 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-12 16:15

Updated : 2025-12-15 15:15


NVD link : CVE-2025-11700

Mitre link : CVE-2025-11700

CVE.ORG link : CVE-2025-11700


JSON object : View

Products Affected

n-able

  • n-central
CWE
CWE-611

Improper Restriction of XML External Entity Reference