Back to Database
Status published
Medium
CVE-2025-12101
Cross-Site Scripting (XSS)
Vulnerability Description
Cross-Site Scripting (XSS) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-12101
Credits & Attribution
No credits recorded in the NVD database.
More from NetScaler
View All →CVE-2025-8424
Improper access control on the NetScaler Management Interface
High
8.7
CVE-2025-7776
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
High
8.8
CVE-2025-7775
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
Critical
9.2
CVE-2025-6543
Memory overflow vulnerability leading to unintended control flow and Denial of Service
Critical
9.2
CVE-2025-5777
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
Critical
9.3
Affected Vendor
NetScaler
View all reports →Affected Software
ADC, Gateway
Vulnerable Versions:
14.1, 13.1, 13.1-FIPS and NDcPP, 12.1-FIPS and NDcPP
Timeline
Official Publish:
November 11th, 2025
Last Modified:
November 12th, 2025
Added to House:
July 22nd, 2026