Vulnerability record · CVE-2025-8875 · published 14 August 2025
CVE-2025-8875: N-able N-central deserialization of untrusted data allows code execution
N Able · N Central
N-able N-central contains a deserialization of untrusted data flaw (CWE-502) that permits code execution. It affects N-central versions before 2025.3.1, and the vendor released a fixed build. Because N-central is remote monitoring and management software, a compromise can expose managed endpoints and customer environments.
Description
Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityCVSS 4.0 base score is 9.4 (critical) and the flaw is in CISA KEV with known exploitation, so it warrants immediate remediation.
What it is
N-able N-central contains a deserialization of untrusted data flaw (CWE-502) that permits code execution. It affects N-central versions before 2025.3.1, and the vendor released a fixed build. Because N-central is remote monitoring and management software, a compromise can expose managed endpoints and customer environments.
Impact
An attacker who can reach the vulnerable deserialization path can execute code in the context of the N-central service, with high impact to confidentiality, integrity and availability of both the vulnerable system and connected systems.
Attack surface
The CVSS 4.0 vector is network reachable (AV:N) with low privileges required (PR:L) and no user interaction (UI:N), so an authenticated low-privileged user can trigger it remotely. No pre-authentication path is indicated by the record.
Exploitation
CVE-2025-8875 is listed in CISA KEV with a due date of 2025-08-20, indicating known exploitation in the wild. EPSS 30-day probability is 0.01721 (76th percentile), and no ransomware campaign use is documented.
What to do
- Upgrade N-central to 2025.3.1 or later per the vendor release notes.
- If immediate patching is not possible, apply the vendor mitigations referenced in the CISA KEV entry or discontinue use of the product.
- Restrict network access to the N-central management interface to trusted administrative networks.
- Review and reduce accounts with access to N-central, removing unnecessary low-privileged users.
- Monitor for post-exploitation activity on N-central hosts and connected managed endpoints.
Detection
- Hunt for unexpected child processes spawned by the N-central service or its application server.
- Review N-central and host logs for deserialization errors, unusual object payloads, or anomalous requests to management endpoints.
- Audit authentication and administrative activity for new or unexpected accounts and privilege changes.
- Check for outbound connections from N-central hosts to unfamiliar external addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-8875 to the Known Exploited Vulnerabilities catalog on 13 August 2025 as "N-able N-Central Insecure Deserialization Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 20 August 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://status.n-able.com/2025/08/13/announcing-the-ga-of-n-central-2025-3-1/ | Release Notes |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-8875 | US Government Resource |
Track CVE-2025-8875 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-8875), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.