CVE-2025-11700

Published Nov 12, 2025

Last updated 3 months ago

Overview

Description
N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure
Source
a5532a13-c4dd-4202-bef1-e0b8f2f8d12b
NVD status
Modified
Products
n-central

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.4
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
HIGH

Weaknesses

a5532a13-c4dd-4202-bef1-e0b8f2f8d12b
CWE-611

Social media

Hype score
Not currently trending
  1. 🚨 CVE-2025-11700 - high 🚨 N-central - XML External Entities Injection &gt; N-central versions &lt; 2025.4 are vulnerable to an XML External Entities injection lead... 👾 https://t.co/7irGSruCCj @pdnuclei #NucleiTemplates #cve

    @pdnuclei_bot

    29 Nov 2025

    271 Impressions

    2 Retweets

    5 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  2. csirt_it: La Settimana Cibernetica del 23 novembre 2025 🔹 aggiornamenti per molteplici prodotti 🔹 N-able: disponibile PoC per lo sfruttamento delle CVE-2025-9316 e CVE-2025-11700 🔹 Operational Summary - ottobre 2025 ⚠️ #EPSS 🔗 … https://t.co/RJmJvcGdyK

    @Vulcanux_

    24 Nov 2025

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. La Settimana Cibernetica del 23 novembre 2025 🔹 aggiornamenti per molteplici prodotti 🔹 N-able: disponibile PoC per lo sfruttamento delle CVE-2025-9316 e CVE-2025-11700 🔹 Operational Summary - ottobre 2025 ⚠️ #EPSS 🔗 https://t.co/SHA1C4I9FP https://t.co/tdrcO

    @csirt_it

    24 Nov 2025

    129 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 New plugin: NCentralPlugin (CVE-2025-9316, CVE-2025-11700). N-able N-Central session bypass and XXE vulnerability detection - XXE allows reading critical files. Results: https://t.co/h2G8mBdDck https://t.co/yLbBN1bZQc

    @leak_ix

    20 Nov 2025

    791 Impressions

    2 Retweets

    6 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  5. csirt_it: ‼️ N-able: disponibile #PoC per lo sfruttamento delle CVE-2025-9316 e CVE-2025-11700 presenti nella piattaforma di RMM N-central Rischio: 🔴 Tipologia: 🔸Authentication Bypass 🔸Arbitrary File Read 🔗 https://t.co/7vva15WJY8 🔄 Aggiornament… https://

    @Vulcanux_

    20 Nov 2025

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. ‼️ N-able: disponibile #PoC per lo sfruttamento delle CVE-2025-9316 e CVE-2025-11700 presenti nella piattaforma di RMM N-central Rischio: 🔴 Tipologia: 🔸Authentication Bypass 🔸Arbitrary File Read 🔗 https://t.co/EYSKk1vXkQ 🔄 Aggiornamenti disponibili 🔄 htt

    @csirt_it

    20 Nov 2025

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. N-able has released security advisories for multiple N-central vulnerabilities. @Horizon3Attack discovered and disclosed these two vulnerabilities in August: ➡️ CVE-2025-9316 is an authentication bypass enabling interaction with sensitive N-central APIs. ➡️ CVE-2025-1170

    @Horizon3ai

    13 Nov 2025

    100 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    1 Reply

    0 Quotes

  8. CVE-2025-11700 XML External Entities Injection in SolarWinds N-central V... https://t.co/klLPeuHLLe Don't wait vulnerability scanning results: https://t.co/oh1APvMMnd

    @VulmonFeeds

    12 Nov 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.