CVE-2025-67835
PRTG Network Monitor vulnerability analysis and mitigation

Overview

CVE-2025-67835 is an uncontrolled resource consumption vulnerability in Paessler PRTG Network Monitor that allows authenticated attackers to trigger a Denial-of-Service (DoS) condition via the Notification Contacts functionality. It affects all versions of PRTG Network Monitor prior to 25.4.114.1032. The CVE was published on January 14, 2026, with initial NVD analysis completed on January 20, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium), assessed by CISA-ADP (Paessler Advisory, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-400 (Uncontrolled Resource Consumption), meaning the application fails to properly limit the resources consumed when processing input through the Notification Contacts feature. An authenticated attacker with low-privilege credentials can send crafted requests to this functionality over the network, causing excessive resource consumption that degrades or crashes the PRTG service. No user interaction is required, and attack complexity is low, making it straightforward to exploit once valid credentials are obtained. No public technical write-up or proof-of-concept code has been identified at this time (Paessler Advisory, Red Hat CVE).

Impact

Successful exploitation disrupts the availability of PRTG Network Monitor, preventing legitimate administrators and users from accessing network monitoring data, dashboards, and alerts. The attack has no impact on confidentiality or integrity — only availability is affected. Because PRTG is commonly deployed as a critical network monitoring platform, its unavailability could blind operations teams to network incidents, outages, or security events during the attack window (Paessler Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.04%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires valid (low-privilege) credentials, which limits opportunistic exploitation but does not eliminate insider or credential-compromise scenarios (Red Hat CVE, Paessler Advisory).

Mitigation and workarounds

Paessler has released a patch in PRTG Network Monitor version 25.4.114.1032, which resolves this vulnerability. Organizations should upgrade to this version or later as the primary remediation step. As interim mitigations, administrators should restrict access to the PRTG web interface to trusted networks and personnel, enforce strong credential hygiene, and monitor system resource utilization for anomalous spikes that could indicate exploitation attempts. Audit logs should be reviewed for unusual configuration changes to Notification Contacts (Paessler Advisory).

Additional resources


SourceThis report was generated using AI

Related PRTG Network Monitor vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-67835MEDIUM6.5
  • PRTG Network Monitor logoPRTG Network Monitor
  • cpe:2.3:a:paessler:prtg_network_monitor
NoYesJan 14, 2026
CVE-2025-67833MEDIUM6.1
  • PRTG Network Monitor logoPRTG Network Monitor
  • cpe:2.3:a:paessler:prtg_network_monitor
NoYesJan 14, 2026
CVE-2024-12833MEDIUM6.1
  • PRTG Network Monitor logoPRTG Network Monitor
  • cpe:2.3:a:paessler:prtg_network_monitor
NoYesFeb 11, 2025
CVE-2023-51630MEDIUM6.1
  • PRTG Network Monitor logoPRTG Network Monitor
  • cpe:2.3:a:paessler:prtg_network_monitor
NoYesFeb 08, 2024
CVE-2025-67834MEDIUM5.4
  • PRTG Network Monitor logoPRTG Network Monitor
  • cpe:2.3:a:paessler:prtg_network_monitor
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management