CVE-2025-32991: n2w Backup& Recovery
Critical severity, CVSS 9.0. EPSS: 0.3% chance of exploitation in the next 30 days.
In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution.
Affected products
- n2w Backup& Recovery: before 4.3.2 (fixed in 4.3.2)
Published 2026-03-25. Last modified 2026-06-17.