CVE-2025-32991Disclosure(n2w / backup\&_recovery)

LOWCVSS 9.0 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution.

1.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Other references
Weakness type (CWE)
CWE-362

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • backup\&_recovery

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-03-26)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
backup\&_recovery

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-25: 1Mentions · 2026-03-26: 2PoC Mentioned / Linked · 2026-03-26: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-26: 103-2503-26
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-251
Disclosure1
2026-03-262
Disclosure1General1
Full discourse3 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2025-32991 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-32991 #CVE-2025-32991 #CVE   #CyberSecurity #InfoSec https://t.co/cGq1RJMTH4

    Post summary

    A brief announcement of CVE-2025-32991 with minimal detail and no evidence of PoC, exploit, active exploitation, patch, or technical specifics.

    00000130
    114 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-32991 - Critical In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution. https://www.thehackerwire.com/vulnerability/CVE-2025-32991/ https://t.co/bqsYBnuw6h

    Post summary

    A critical vulnerability (CVE‑2025‑32991) is disclosed, detailing a two‑step RCE via the RESTful API in N2WS Backup & Recovery versions prior to 4.4.0, with a link to further details.

    00000158
    148 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-32991: CRITICAL] In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution.#cve,CVE-2025-32991,#cybersecurity https://cvefind.com/CVE-2025-32991

    Post summary

    CVE‑2025‑32991 is a critical remote code execution flaw in N2WS Backup & Recovery versions prior to 4.4.0, where a two‑step attack on the RESTful API can be used to gain code execution. No PoC, exploit code, patch, or evidence of active exploitation is mentioned.

    0000063
    605 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appn2wbackup\&_recovery---

Explore more