漏洞描述 Citrix旗下多款交付控制器和网关存在RCE漏洞,攻击者在无需身份验证的情况下就可执行任意命令。CitrixADC(NetScalers)中的目录穿越错误,这个错误会调用perl脚本,perl脚本用于将XML格式的文件附加到受害计算机,因此产生远程执行代码。
相关漏洞推荐 (CVE-2025-5777)Citrix NetScaler管理接口输入验证不足导致内存读取越界漏洞 CVE-2019-19781: Citrix Application Delivery Controller (ADC) and Gateway Directory Traversal. POC CVE-2025-5777: Citrix NetScaler Memory Disclosure - CitrixBleed 2 POC CVE-2019-12985: Citrix SD-WAN Center - Remote Command Injection POC CVE-2019-12986: Citrix SD-WAN Center - Remote Command Injection POC CVE-2019-12987: Citrix SD-WAN Center - Remote Command Injection POC CVE-2019-12988: Citrix SD-WAN Center - Remote Command Injection POC CVE-2019-12990: Citrix SD-WAN Center - Local File Inclusion POC CVE-2019-19781: Citrix ADC and Gateway - Directory Traversal POC CVE-2020-8191: Citrix ADC/Gateway - Cross-Site Scripting POC CVE-2020-8193: Citrix - Local File Inclusion POC CVE-2020-8194: Citrix ADC and Citrix NetScaler Gateway - Remote Code Injection POC CVE-2020-8209: Citrix XenMobile Server - Local File Inclusion