In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution.
References
| Link | Resource |
|---|---|
| https://n2ws.com/blog/security-advisory-update | Vendor Advisory |
| https://www.n2ws.com | Product |
Configurations
History
26 Mar 2026, 20:36
| Type | Values Removed | Values Added |
|---|---|---|
| CPE |
26 Mar 2026, 20:31
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:n2w:backup\&_recovery:*:*:*:*:*:*:*:* cpe:2.3:a:n2w:backup\&_recovery:4.4.0:*:*:*:*:*:*:* |
|
| First Time |
N2w
N2w backup\& Recovery |
|
| References | () https://n2ws.com/blog/security-advisory-update - Vendor Advisory | |
| References | () https://www.n2ws.com - Product |
25 Mar 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-362 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.0 |
25 Mar 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-25 15:16
Updated : 2026-03-26 20:36
NVD link : CVE-2025-32991
Mitre link : CVE-2025-32991
CVE.ORG link : CVE-2025-32991
JSON object : View
Products Affected
n2w
- backup\&_recovery
CWE
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
