CVE-2025-11700 is an XML External Entity (XXE) injection vulnerability affecting N-able N-central versions earlier than 2025.4. The provided content describes the issue as involving multiple XXE injection points that can lead to information disclosure. Available supporting context further indicates that, when this flaw is chained with CVE-2025-9316 (an unauthenticated session bypass), an attacker can perform unauthenticated local file reads against affected N-central instances, including reading sensitive application backup files and other files accessible on the host system. Specific vulnerable functions or request handlers are not identified in the provided material.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a single Go source file implementing a Goby Goscanner exploit module for CVE-2025-11700 (N-able N-central XXE in SOAP services prior to 2025.4). Structure & purpose: - One file: `N_central _dms_services_ServerMMS_XML_External_Entity_Injection_Vulnerability_CVE-2025-11700.go`. - Registers an exploit definition (JSON metadata) with Goby’s scanner framework, including FOFA/Goby fingerprints, CVE, severity, and user parameters. Exploit flow (high level): - Performs a basic GET / check for reachability. - Core logic in `doExploit_4a2b9d(u, dtdUrl)`: - Step 1: Sends a SOAP `sessionHello` request to `/dms/services/ServerUI` to obtain a SessionID (used to proceed with subsequent SOAP interactions). - Subsequent steps (partially truncated in provided content) upload/submit an XML payload that references an attacker-controlled external entity/DTD URL and then triggers parsing on `/dms/services/ServerMMS`, causing either: - Out-of-band interaction to the provided OOB URL/domain (DNS/HTTP), or - Error-based leakage where file contents (e.g., `/etc/passwd`) appear in the SOAP fault response. Capabilities: - Unauthenticated network exploitation against exposed N-central SOAP endpoints. - XXE-based information disclosure (arbitrary file read) and OOB verification. - Two operating modes: - Scan mode: auto-generates an OOB URL via Goby GodClient and confirms via `PullExists`. - Exploit mode: uses user-supplied `attack_url` (DNSLog or hosted DTD) and reports either leaked content (e.g., detects `root:`) or instructs to check OOB server. Notable implementation details: - TLS verification is disabled for the SOAP POST in step 1 (`VerifyTls = false`), easing exploitation against self-signed deployments. - Provides a recommended error-based DTD snippet to coerce file content into an error path for direct response retrieval.
This repository contains a proof-of-concept exploit for unauthenticated XXE (XML External Entity) vulnerabilities in N-able N-central, chaining CVE-2025-9316 and CVE-2025-11700 to read arbitrary files from the target server. The exploit is implemented in a single Python script ('ncentral_xxe_file_read.py') and is accompanied by a README.md with usage instructions and background information. The script works by: 1. Starting a local HTTP server (DTD server) to serve a malicious DTD file. 2. Sending a crafted SOAP request to the target N-central instance to obtain a session ID. 3. Triggering the XXE vulnerability by sending a specially crafted XML payload that references the attacker's DTD server. 4. Causing the target to read a specified file (default: /etc/passwd) and exfiltrate its contents to the attacker. The script allows the attacker to specify the target URL, the file to read, and the IP/port for the DTD server. It also includes a test mode to check endpoint accessibility. The main attack vector is network-based, targeting the SOAP endpoints '/dms/services/ServerUI' and '/dms/services/ServerMMS' on the N-central server. The exploit is a functional proof-of-concept and does not include weaponized features such as automated credential extraction or post-exploitation modules.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated XML External Entity (XXE) vulnerability in N-able N-Central that allows attackers to read arbitrary files from the host system.
A vulnerability in N-able N-central. Details not specified in the content, but it is listed as a serious security flaw for the week.
An XML External Entity (XXE) vulnerability affecting N-able N-Central that can be combined with CVE-2025-9316 to achieve unauthenticated file read on affected instances.
An XML External Entities (XXE) injection vulnerability affecting N-central, as referenced in a GitHub pull request for a Nuclei detection template update.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.