CVE-2025-5777

HIGH KEV RANSOMWARE NUCLEI

Citrix Netscaler Application Delivery... - Use of Uninitialized Resource

Title source: rule

Description

Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

Exploits (29)

exploitdb WORKING POC
by Yesith Alvarez · pythonremotemultiple
https://www.exploit-db.com/exploits/52401
nomisec WORKING POC 45 stars
by win3zz · infoleak
https://github.com/win3zz/CVE-2025-5777
nomisec WORKING POC 30 stars
by bughuntar · infoleak
https://github.com/bughuntar/CVE-2025-5777
nomisec WORKING POC 17 stars
by mingshenhk · poc
https://github.com/mingshenhk/CitrixBleed-2-CVE-2025-5777-PoC-
nomisec SCANNER 7 stars
by Chocapikk · infoleak
https://github.com/Chocapikk/CVE-2025-5777
nomisec WORKING POC 4 stars
by soltanali0 · infoleak
https://github.com/soltanali0/CVE-2025-5777-Exploit
nomisec WORKING POC 3 stars
by ndr-repo · poc
https://github.com/ndr-repo/CVE-2025-5777
nomisec WORKING POC 3 stars
by Shivshantp · poc
https://github.com/Shivshantp/CVE-2025-5777-TrendMicro-ApexCentral-RCE
nomisec WORKING POC 3 stars
by nocerainfosec · infoleak
https://github.com/nocerainfosec/cve-2025-5777
nomisec WORKING POC 2 stars
by cyberleelawat · infoleak
https://github.com/cyberleelawat/ExploitVeer
nomisec WORKING POC 2 stars
by orange0Mint · infoleak
https://github.com/orange0Mint/CitrixBleed-2-CVE-2025-5777
nomisec WORKING POC 1 stars
by RickGeex · poc
https://github.com/RickGeex/CVE-2025-5777-CitrixBleed
nomisec WORKING POC
by 0xBlackash · poc
https://github.com/0xBlackash/CVE-2025-5777
nomisec WORKING POC
by 0xAshwesker · poc
https://github.com/0xAshwesker/CVE-2025-5777
nomisec WORKING POC
by zaryouhashraf · poc
https://github.com/zaryouhashraf/CVE-2025-5777
nomisec WORKING POC
by FrenzisRed · infoleak
https://github.com/FrenzisRed/CVE-2025-5777
nomisec WORKING POC
by rashedhasan090 · infoleak
https://github.com/rashedhasan090/CVE-2025-5777
nomisec WORKING POC
by Anshika2709 · poc
https://github.com/Anshika2709/Citrixbleed2-CVE-2025-5777
nomisec STUB
by mr-r3b00t · poc
https://github.com/mr-r3b00t/CVE-2025-5777
nomisec WORKING POC
by rob0tstxt · infoleak
https://github.com/rob0tstxt/POC-CVE-2025-5777
nomisec WORKING POC
by rootxsushant · infoleak
https://github.com/rootxsushant/Citrix-NetScaler-Memory-Leak-CVE-2025-5777
nomisec WRITEUP
by below0day · poc
https://github.com/below0day/Honeypot-Logs-CVE-2025-5777
nomisec WORKING POC
by SleepNotF0und · infoleak
https://github.com/SleepNotF0und/CVE-2025-5777
nomisec WORKING POC
by 0xgh057r3c0n · infoleak
https://github.com/0xgh057r3c0n/CVE-2025-5777
nomisec WORKING POC
by idobarel · infoleak
https://github.com/idobarel/CVE-2025-5777
nomisec SCANNER
by RaR1991 · infoleak
https://github.com/RaR1991/citrix_bleed_2

Nuclei Templates (1)

Citrix NetScaler Memory Disclosure - CitrixBleed 2
CRITICALVERIFIEDby watchtowr,DhiyaneshDk,darses
Shodan: title:"NetScaler Gateway" || title:"NetScaler AAA" || http.favicon.hash:-1166125415 || http.favicon.hash:-1292923998
FOFA: title="NetScaler Gateway" || title="NetScaler AAA" || icon_hash="-1166125415" || icon_hash="-1292923998"

Scores

CVSS v3 7.5
EPSS 0.6667
EPSS Percentile 98.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CISA KEV 2025-07-10
VulnCheck KEV 2025-06-26
ENISA EUVD EUVD-2025-18497
Ransomware Use Confirmed
CWE
CWE-125 CWE-457 CWE-908
Status published
Products (4)
citrix/netscaler_application_delivery_controller 12.1 - 12.1-55.328
citrix/netscaler_application_delivery_controller 13.1 - 13.1-37.235
citrix/netscaler_application_delivery_controller 13.1 - 13.1-58.32
citrix/netscaler_gateway 13.1 - 13.1-58.32
Published Jun 17, 2025
KEV Added Jul 10, 2025
Tracked Since Feb 18, 2026