In N2W before 4.3.2 and 4.4.x before 4.4.1, there is potential remote code execution and account credentials theft because of a spoofing vulnerability.
References
| Link | Resource |
|---|---|
| https://n2ws.com/blog/security-advisory-update | Vendor Advisory |
| https://n2ws.zendesk.com/hc/en-us/articles/29817965452701-Release-notes-for-N2W-V4-3-2-August-2025 | Release Notes |
| https://www.n2ws.com | Product |
Configurations
History
26 Mar 2026, 20:36
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://n2ws.com/blog/security-advisory-update - Vendor Advisory | |
| References | () https://n2ws.zendesk.com/hc/en-us/articles/29817965452701-Release-notes-for-N2W-V4-3-2-August-2025 - Release Notes | |
| References | () https://www.n2ws.com - Product | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| CWE | CWE-290 | |
| First Time |
N2w
N2w n2w |
|
| CPE | cpe:2.3:a:n2w:n2w:*:*:*:*:*:*:*:* cpe:2.3:a:n2w:n2w:4.4.0:*:*:*:*:*:*:* |
25 Mar 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-25 15:16
Updated : 2026-03-27 05:16
NVD link : CVE-2025-59707
Mitre link : CVE-2025-59707
CVE.ORG link : CVE-2025-59707
JSON object : View
Products Affected
n2w
- n2w
CWE
CWE-290
Authentication Bypass by Spoofing
