References https://me.n-able.com/s/security-advisory/aArVy0000000rabKAA/cve202511700-ncentral-importservicefromfile-xxe-injection https://horizon3.ai/attack-research/vulnerabilities/n-able-n-central-vulnerabilities-cve-2025-9316-cve-2025-11700/ https://nvd.nist.gov/vuln/detail/CVE-2025-11700 https://www.cvedetails.com/cve/CVE-2025-11700/ https://github.com/advisories/GHSA-89f8-292w-gfh4 https://horizon3.ai/attack-research/attack-blogs/n-able-n-central-from-n-days-to-0-days/ https://pentest-tools.com/vulnerabilities-exploits/n-central-xml-external-entities-injection_28152 https://s4e.io/tools/n-central-xml-external-entities-injection-cve-2025-11700 https://github.com/horizon3ai/n-able_n-central_xxe_file_read https://www.tenable.com/cve/CVE-2025-11700
Related VulnerabilitiesPoCCVE-2026-86206: N-able N-central - Access Control Bypass via Path Confusion and Forwarded Header SpoofingPoCCVE-2026-86207: N-able N-central - Authentication BypassPoCCVE-2026-18577: N-able N-central < 2026.3.1.10 - Authentication BypassMagnolia CMS /.magnolia/admincentral 默认口令漏洞PoCCVE-2024-28200: N-able N-central < 2024.2 - Authentication Bypass DetectionN-central /dms/services/ServerMMS XML 外部实体注入漏洞(CVE-2025-11700)PoCCVE-2025-11700: N-central - XML External Entities InjectionPoCCVE-2025-9316: N-central - Authentication BypassQNAP Qsync Central 路径遍历漏洞QNAP Qsync Central SQL注入漏洞PoCCVE-2018-15517: D-Link Central WifiManager - Server-Side Request Forgery