A memory overflow vulnerability in NetScaler ADC and NetScaler Gateway may allow Remote Code Execution or Denial of Service when configured as Gateway (VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. It also affects LB virtual servers of type HTTP, SSL, or HTTP_QUIC bound to IPv6 services or service groups.
It affects versions 13.1 before 13.1-59.22, 14.1 before 14.1-47.48, 13.1-FIPS and NDcPP before 13.1-37.241, and 12.1-FIPS and NDcPP before 12.1-55.330.
Exploits of CVE-2025-7775 on unmitigated appliances have been observed in the wild.
The IONIX research team is tracking ongoing exploitation attempts and recommends follow the vendor security bulletin. Potentially affected assets are outlined in this post.
References:

