CVE-2025-10589: N-Partner N-Cloud
High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.
The N-Reporter, N-Cloud, and N-Probe developed by N-Partner has an OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the server.
Affected products
- N-Partner N-Cloud: from 6, before 6.1.187 (fixed in 6.1.187); from 7, before 7.0.009 (fixed in 7.0.009)
- N-Partner N-Probe: from 6, before 6.1.187 (fixed in 6.1.187); from 7, before 7.0.009 (fixed in 7.0.009)
- N-Partner N-Reporter: from 6, before 6.1.187 (fixed in 6.1.187); from 7, before 7.0.009 (fixed in 7.0.009)
Published 2025-09-17. Last modified 2026-06-17.