CVE-2025-32406
CVSS 3.1 Score 8.6 of 10 (high)
Details
Published Apr 8, 2025
CWE ID 611
Summary
CVE-2025-32406 is a vulnerability affecting the Director NBR component in NAKIVO Backup & Replication versions 10.3.x through 11.0.1, prior to 11.0.2. This issue represents a XML External Entity (XXE) injection vulnerability, enabling remote attackers to fetch and parse XML responses. Successful exploitation could result in the disclosure of sensitive information or even arbitrary code execution. It is recommended that users upgrade to the latest version, 11.0.2, to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.