OS Command Injection Vulnerability in N-Reporter, N-Cloud, and N-Probe by N-Partner
CVE-2025-10589

8.7HIGH

Key Information:

Vendor

N-partner

Vendor
CVE Published:
17 September 2025

What is CVE-2025-10589?

The OS Command Injection vulnerability in N-Reporter, N-Cloud, and N-Probe developed by N-Partner allows authenticated remote attackers to inject and execute arbitrary operating system commands on the server. This could lead to unauthorized access and potential compromise of sensitive data, emphasizing the need for immediate security measures and software updates.

Affected Version(s)

N-Cloud 6 < 6.1.187

N-Cloud 7 < 7.0.009

N-Probe 6 < 6.1.187

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-10589 : OS Command Injection Vulnerability in N-Reporter, N-Cloud, and N-Probe by N-Partner