CVE-2025-32406

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Apr 8, 2025
CWE ID 611

Summary

CVE-2025-32406 is a vulnerability affecting the Director NBR component in NAKIVO Backup & Replication versions 10.3.x through 11.0.1, prior to 11.0.2. This issue represents a XML External Entity (XXE) injection vulnerability, enabling remote attackers to fetch and parse XML responses. Successful exploitation could result in the disclosure of sensitive information or even arbitrary code execution. It is recommended that users upgrade to the latest version, 11.0.2, to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share