A high-severity vulnerability, CVE-2025-5349, has been identified in NetScaler ADC and NetScaler Gateway when the management interface is exposed via NSIP, Cluster Management IP, or site-local GSLB IP. The flaw stems from improper access control and may allow unauthorized users to access sensitive functionality without authentication. This impacts multiple versions prior to 14.1-43.56 and 13.1-58.32. The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially exposed assets are outlined in this post.
References:

