Executive brief
N-able N-central is a remote monitoring and management platform used by IT professionals to manage large networks of computers. A security flaw allows an attacker with low-level access to run unauthorized commands on the server, potentially leading to a full takeover of the management system and the client networks it controls. This vulnerability has been observed being used in active attacks, making immediate updates critical to prevent data theft or service disruption.
Technical details
An OS command injection vulnerability exists in N-able N-central due to improper input validation (CWE-20) and neutralization of special elements (CWE-78). A remote attacker with low-privileged (PR:L) network access can exploit this flaw to execute arbitrary commands on the underlying operating system. The vulnerability has a high impact on confidentiality, integrity, and availability (VC:H/VI:H/VA:H) and has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog. Users should upgrade to N-central version 2025.3.1 or later to remediate the issue.
Affected products
- N-able N-central before 2025.3.1
Timeline
- 2025-08-13: disclosed: Initial publication and release of version 2025.3.1
- 2025-08-13: kev added: Added to CISA KEV catalog due to active exploitation
- 2025-08-14: advisory: NVD entry published