CVE-2025-59706

CRITICAL

N2W <4.3.2 and 4.4.0 - API Parameter Remote Code Execution

Title source: manual
STIX 2.1

Description

In N2W before 4.3.2 and 4.4.0 before 4.4.1, improper validation of API request parameters enables remote code execution.

Scores

CVSS v3 9.8
EPSS 0.0053
EPSS Percentile 40.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-290
Status published
Products (2)
n2w/n2w < 4.3.2
n2ws/n2w < 4.3.2
Published Mar 25, 2026
Tracked Since Mar 25, 2026