Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-5777 PoC — NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread

Source
Associated Vulnerability
Title: NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread (CVE-2025-5777)
Description:Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
Description
An advanced, powerful, and easy-to-use tool designed to detect and exploit CVE-2025-5777 (CitrixBleed 2). This script not only identifies the vulnerability but also helps in demonstrating its impact by parsing human-readable information from the memory leak.
Readme
# CVE-2025-5777: The Ultimate Scanner 🚀
![Hacker](https://media.giphy.com/media/LmNwrBhejkK9EFP504/giphy.gif)

---

### 🔐 CVE: `CVE-2025-5777`  
### 🚨 Severity: **Critical**  
### 👨‍💻 Author: `Virendra Kumar & CyberLeelawat`  
### 📜 License: [MIT](./LICENSE)

---

An advanced, powerful, and easy-to-use tool designed to detect and exploit **CVE-2025-5777** (aka **CitrixBleed 2**).  
This script not only identifies the memory leak vulnerability but **demonstrates real-world impact** by parsing sensitive data like session cookies and credentials directly from leaked memory.

---

## 🧠 What is CVE-2025-5777?

`CVE-2025-5777` is a **critical memory leak vulnerability** in **NetScaler (Citrix) ADC and Gateway** products.

> 🧨 It allows unauthenticated, remote attackers to **leak sensitive memory content** like:
- Session cookies (e.g., `NSC_AAAC`)
- Usernames and passwords
- MFA tokens and more

This can result in **full account takeover** without credentials or MFA, making it a **high-impact RCE-level vulnerability**.

---

## ✨ Features

✅ **High-Speed Asynchronous Scanning**  
→ Built with `asyncio` & `aiohttp` to scan targets blazing fast.  

✅ **Intelligent Data Extraction**  
→ Parses **human-readable strings** from leaked memory (like creds, tokens).  

✅ **Sensitive Data Detection**  
→ Detects critical patterns like session cookies and flags high-risk data.  

✅ **Leak Reporting**  
→ Automatically stores leaks into `leaks.txt` for clean offline analysis.  

✅ **PoC + Exploitation Loop**  
→ Supports one-time check or continuous exploitation mode with `--check` flag.  

---

## ⚠️ Disclaimer

> ❗ **This tool is for educational and authorized bug bounty testing only.**  
> ❌ Unauthorized use on systems you don’t own or have permission to test is **illegal**.  
> 🧑‍💻 The author is not responsible for any misuse or damage caused by this tool.

---



## 📚 Official References

- [NIST NVD – CVE-2025-5777](https://nvd.nist.gov/vuln/detail/CVE-2025-5777)
- [Citrix Security Advisory – CTX693420](https://support.citrix.com/article/CTX693420)

---

## 🔍 Shodan Dorks

- http.html:"_ctxstxt_NetscalerAAA" ssl.cert.subject.CN:"target.com" port:6443

- title:"Netscaler Gateway" ssl.cert.subject.CN:"target.com" port:6443

- title:"NetScaler AAA" ssl.cert.subject.CN:"target.com" port:6443

- http.favicon.hash:-1166125415 ssl.cert.subject.CN:"target.com" port:6443

- http.favicon.hash:-1292923998 ssl.cert.subject.CN:"target.com" port:6443


---

## 🔎 Google Dorks

- inurl:/logon/LogonPoint/tmindex.html site:target.com


---

## 🌀 Curl Command

```bash
curl -s -k -X POST "https://target.com/p/u/doAuthentication.do" -d "login"
``` 

Exploit Payload Path
```https://target.com/p/u/doAuthentication.do``` 
Use Burp Suite to capture and manipulate the request.

## 🙏 Credits & Acknowledgements
- Tool Developer: Virendra Kumar & CyberLeelawat
- Original Vulnerability Research: The foundational research and original exploit concepts for this vulnerability were published by security researchers at Watchtwr Labs and others in the community. This tool builds upon their essential work.

---

📜 License
This project is licensed under the MIT License – see the LICENSE file for details.


File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →