CVE-2025-10589: N-Partner N-Cloud

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

The N-Reporter, N-Cloud, and N-Probe developed by N-Partner has an OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the server.

Affected products

  • N-Partner N-Cloud: from 6, before 6.1.187 (fixed in 6.1.187); from 7, before 7.0.009 (fixed in 7.0.009)
  • N-Partner N-Probe: from 6, before 6.1.187 (fixed in 6.1.187); from 7, before 7.0.009 (fixed in 7.0.009)
  • N-Partner N-Reporter: from 6, before 6.1.187 (fixed in 6.1.187); from 7, before 7.0.009 (fixed in 7.0.009)

Published 2025-09-17. Last modified 2026-06-17.