CVE-2025-32991

In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:n2w:backup\&_recovery:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-25 15:16

Updated : 2026-03-26 20:36


NVD link : CVE-2025-32991

Mitre link : CVE-2025-32991

CVE.ORG link : CVE-2025-32991


JSON object : View

Products Affected

n2w

  • backup\&_recovery
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')