In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution.
References
| Link | Resource |
|---|---|
| https://n2ws.com/blog/security-advisory-update | Vendor Advisory |
| https://www.n2ws.com | Product |
Configurations
History
No history.
Information
Published : 2026-03-25 15:16
Updated : 2026-03-26 20:36
NVD link : CVE-2025-32991
Mitre link : CVE-2025-32991
CVE.ORG link : CVE-2025-32991
JSON object : View
Products Affected
n2w
- backup\&_recovery
CWE
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
