Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
n-able_n-central_xxe_file_read — Proof of concept exploit for N-able N-central to chain CVE-2025-9316 and CVE-2025-11700 to read files | Kitploit
Tools/GitHubGitHub/horizon3ai/n-able_n-central_xxe_file_read
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration TestingRed Teaming
GitHubhorizon3ai/n-able_n-central_xxe_file_read

n-able_n-central_xxe_file_read

Proof of concept exploit for N-able N-central to chain CVE-2025-9316 and CVE-2025-11700 to read files

View Repository
3310 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

N-able N-central Unauthenticated XXE Sensitive Information Leak

Proof of concept exploit for N-able N-central to chain CVE-2025-9316 and CVE-2025-11700 to read files which contain credentials

Blog Post

Deep-dive analysis here: https://www.horizon3.ai/attack-research/attack-blogs/n-able-n-central-from-n-days-to-0-days/

Usage

% python3 ncentral_xxe_file_read.py -h
usage: ncentral_xxe_file_read.py [-h] --url URL --listen-ip LISTEN_IP --listen-port LISTEN_PORT [--file FILE] [--appliance-id APPLIANCE_ID] [--test-only]

N-able N-Central XXE Vulnerability Exploit

options:
  -h, --help            show this help message and exit
  --url URL             N-Central Base URL
  --listen-ip LISTEN_IP
                        IP address for DTD server to bind to
  --listen-port LISTEN_PORT
                        Port for DTD server to bind to
  --file FILE           Target file to read (default: /etc/passwd)
  --appliance-id APPLIANCE_ID
                        Appliance ID to use (default: 3)
  --test-only           Only test endpoint accessibility

Follow the Horizon3.ai Attack Team on Twitter for the latest security research:

  • Horizon3 Attack Team
  • James Horseman
  • Zach Hanley

Disclaimer

This software has been created purely for the purposes of academic research and for the development of effective defensive techniques, and is not intended to be used to attack systems except where explicitly authorized. Project maintainers are not responsible or liable for misuse of the software. Use responsibly.

Download Tool