CVE-2025-11700: N-central Multiple XXE Injection Vulnerabilities
Published Nov 12, 2025
·Updated
N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure
Affected Software
2 affected components
N-central N-central<2025.4
N-able N-Central<2025.4
Event History
Nov 12, 2025
CVE Published
via MITRE·03:30 PM
Data Sourced
via MITRE·03:30 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-11700?
The severity of CVE-2025-11700 is classified as critical due to its potential for information disclosure.
2
How do I fix CVE-2025-11700?
To fix CVE-2025-11700, upgrade your N-central software to version 2025.4 or later.
3
What is CVE-2025-11700?
CVE-2025-11700 is a vulnerability in N-central versions prior to 2025.4 that allows XML External Entities injection, leading to potential information disclosure.
4
What versions of N-central are affected by CVE-2025-11700?
N-central versions earlier than 2025.4 are affected by CVE-2025-11700.
5
What are the consequences of CVE-2025-11700?
The consequence of CVE-2025-11700 is unauthorized access to sensitive information due to an XML External Entities injection.