
Analysis from the Intruder Security Team
Published Aug 28, 2025 Updated Aug 28, 2025
As this vulnerability is known to have been exploited by real attackers, the patch should be applied immediately.
If you have a vulnerable device connected to the internet, as well as patching, it is important to check that the device was not already compromised.
NCSC-NL, the Dutch National Cybersecurity Centre, have produced a tool available here which can help with this. Note that despite being marked as for an older CVE, this script is also receiving updates to check for issues relating to CVE-2025-7775.
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5920186A-2278-4C5E-A2EE-047C4F6FAACD",
"versionEndExcluding": "12.1-55.330",
"versionStartIncluding": "12.1"
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E09EC98B-E057-4FF7-9B18-EF460A29B876",
"versionEndExcluding": "12.1-55.330",
"versionStartIncluding": "12.1"
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0096548F-A846-4D80-A4C6-71389543630F",
"versionEndExcluding": "13.1-37.241",
"versionStartIncluding": "13.1"
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F40E29F2-8013-41A8-91A5-848FE6365876",
"versionEndExcluding": "13.1-37.241",
"versionStartIncluding": "13.1"
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C2009493-AAFD-4090-84BC-5217A860E42A",
"versionEndExcluding": "13.1-59.22",
"versionStartIncluding": "13.1"
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3487EADF-F387-4DD4-B600-B1EBC416632E",
"versionEndExcluding": "14.1-47.48",
"versionStartIncluding": "14.1"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DBA34500-BFE6-4B33-A52B-326C4C2069B1",
"versionEndExcluding": "13.1-59.22",
"versionStartIncluding": "13.1"
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "004E06F6-0ABF-4414-B2A2-8834C1E6107D",
"versionEndExcluding": "14.1-47.48",
"versionStartIncluding": "14.1"
}
],
"operator": "OR"
}
]
}
]