
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67835 is an uncontrolled resource consumption vulnerability in Paessler PRTG Network Monitor that allows authenticated attackers to trigger a Denial-of-Service (DoS) condition via the Notification Contacts functionality. It affects all versions of PRTG Network Monitor prior to 25.4.114.1032. The CVE was published on January 14, 2026, with initial NVD analysis completed on January 20, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium), assessed by CISA-ADP (Paessler Advisory, Red Hat CVE).
The vulnerability is classified as CWE-400 (Uncontrolled Resource Consumption), meaning the application fails to properly limit the resources consumed when processing input through the Notification Contacts feature. An authenticated attacker with low-privilege credentials can send crafted requests to this functionality over the network, causing excessive resource consumption that degrades or crashes the PRTG service. No user interaction is required, and attack complexity is low, making it straightforward to exploit once valid credentials are obtained. No public technical write-up or proof-of-concept code has been identified at this time (Paessler Advisory, Red Hat CVE).
Successful exploitation disrupts the availability of PRTG Network Monitor, preventing legitimate administrators and users from accessing network monitoring data, dashboards, and alerts. The attack has no impact on confidentiality or integrity — only availability is affected. Because PRTG is commonly deployed as a critical network monitoring platform, its unavailability could blind operations teams to network incidents, outages, or security events during the attack window (Paessler Advisory).
There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.04%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires valid (low-privilege) credentials, which limits opportunistic exploitation but does not eliminate insider or credential-compromise scenarios (Red Hat CVE, Paessler Advisory).
Paessler has released a patch in PRTG Network Monitor version 25.4.114.1032, which resolves this vulnerability. Organizations should upgrade to this version or later as the primary remediation step. As interim mitigations, administrators should restrict access to the PRTG web interface to trusted networks and personnel, enforce strong credential hygiene, and monitor system resource utilization for anomalous spikes that could indicate exploitation attempts. Audit logs should be reviewed for unusual configuration changes to Notification Contacts (Paessler Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."