CVE-2025-12101
massCross-Site Scripting in Citrix NetScaler ADC and NetScaler Gateway
CVE-2025-12101 is a cross-site scripting (XSS, CWE-79) flaw in Citrix NetScaler ADC and NetScaler Gateway that affects appliances only when they are configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server. An attacker can craft input that, when rendered to a user (the CVSS 4.0 vector requires user interaction but no privileges), executes attacker-supplied script in the victim's browser session in the context of the Gateway or AAA pages, with high confidentiality impact per the scoring. Successful exploitation could expose session data or credentials handled through the VPN/AAA portal, but the impact scope is limited to the affected system with low integrity and availability impact. Deployments of NetScaler ADC or NetScaler Gateway that do not use Gateway or AAA virtual servers are not affected. No public proof of concept or confirmed in-the-wild exploitation is known and it is not yet in CISA KEV, but the EPSS score of 25.4% (98th percentile) indicates a significant likelihood of exploitation within 30 days.
What to do: Identify all NetScaler ADC/Gateway appliances with Gateway (VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual servers — especially internet-reachable VPN portals — and upgrade them to the fixed builds listed in the Citrix security bulletin for CVE-2025-12101 (exact fixed versions are not included in this data). As interim measures, restrict untrusted access to the Gateway/AAA endpoints and monitor for exploitation attempts, prioritizing patching given the high EPSS likelihood despite the lack of known in-the-wild exploitation.
| Citrix NetScaler ADC | — |
| Citrix NetScaler Gateway | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Cross-Site Scripting (XSS) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
- Weakness
- CWE-79
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.