XSS Vulnerability in Paessler PRTG Network Monitor
CVE-2025-67833

6.1MEDIUM

Key Information:

Vendor

Paessler

Vendor
CVE Published:
14 January 2026

What is CVE-2025-67833?

The Paessler PRTG Network Monitor software prior to version 25.4.114 has been identified to allow Cross-Site Scripting (XSS) due to improper validation of user inputs via the tag parameter. An unauthenticated attacker can exploit this vulnerability to inject malicious scripts that could compromise user sessions or redirect users to harmful sites.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.