Executive brief
N-able N-central, a remote monitoring and management platform used by IT service providers, contains a critical security flaw. This vulnerability allows an attacker to execute unauthorized commands on the system, potentially leading to a full takeover of the management console and the client networks it oversees. This issue is reportedly being exploited in the wild, making immediate patching essential to protect sensitive customer data and maintain service availability.
Technical details
An insecure deserialization vulnerability (CWE-502) exists in N-able N-central prior to version 2025.3.1. The flaw stems from the application improperly processing untrusted data, which can be manipulated to execute arbitrary code. While some assessments suggest a local attack vector, the vendor-provided CVSS 4.0 score indicates the vulnerability is network-reachable (AV:N) but requires low-level authenticated privileges (PR:L). Successful exploitation allows for full compromise of confidentiality, integrity, and availability (H/H/H). CISA has confirmed active exploitation of this vulnerability, and users are urged to update to version 2025.3.1 or later.
Affected products
- N-able N-central before 2025.3.1
Timeline
- 2025-08-13: disclosed
- 2025-08-13: patched: Fixed in version 2025.3.1
- 2025-08-13: kev added
- 2025-08-13: exploited