HIGH
CVE-2025-8875
CVSS
7.8
KEV
Description
Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.
Summary dbcve.org
N-able N-central versions before 2025.3.1 contain a deserialization vulnerability where untrusted data is being deserialized without proper validation, allowing an authenticated local attacker to execute arbitrary code on the affected system.
Mitigation
Upgrade N-able N-central to version 2025.3.1 or later to remediate this vulnerability. Apply the update following vendor-specific upgrade procedures and verify successful installation.
Weakness (CWE)
CWE-502
Deserialization of Untrusted Data
EPSS Score
1.72%
Probability of exploitation in next 30 days
76.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.