CVE-2025-0133Disclosure

LOWCVSS 2.7 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Networks PAN-OS® software enables execution of malicious JavaScript in the context of an authenticated Captive Portal user's browser when they click on a specially crafted link. The primary risk is phishing attacks that can lead to credential theft—particularly if you enabled Clientless VPN. There is no availability impact to GlobalProtect features or GlobalProtect users. Attackers cannot use this vulnerability to tamper with or modify contents or configurations of the GlobalProtect portal or gateways. The integrity impact of this vulnerability is limited to enabling an attacker to create phishing and credential-stealing links that appear to be hosted on the GlobalProtect portal. For GlobalProtect users with Clientless VPN enabled, there is a limited impact on confidentiality due to inherent risks of Clientless VPN that facilitate credential theft. You can read more about this risk in the informational bulletin PAN-SA-2025-0005 https://security.paloaltonetworks.com/PAN-SA-2025-0005 https://security.paloaltonetworks.com/PAN-SA-2025-0005 . There is no impact to confidentiality for GlobalProtect users if you did not enable (or you disable) Clientless VPN.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • PoC: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-02-01); latest day: 1
  • 5 total mentions across 5 days

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-02-01: 1Mentions · 2026-02-06: 1Mentions · 2026-04-25: 1Mentions · 2026-08-03: 1Mentions · 2026-08-12: 1Technical Details · 2026-02-01: 1Technical Details · 2026-02-06: 1Technical Details · 2026-04-25: 1Technical Details · 2026-08-03: 1Technical Details · 2026-08-12: 102-0102-0604-2508-0308-12
Signal classification3 categories
Disclosure
360.0%
General
120.0%
PoC
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-011
Disclosure1
2026-02-061
Disclosure1
2026-04-251
General1
2026-08-031
PoC1
2026-08-121
Disclosure1
Full discourse5 posts
  • Professor Larry Densel@luckyhacker43
    Disclosure

    How I Discovered CVE-2025–0133 – Reflected XSS with Shodan Recon by Zuksh 🤯🔥 🔗 https://zuksh.medium.com/how-i-discovered-cve-2025-0133-reflected-xss-with-shodan-recon-33297703bfc0 🔗 Join team 👉 http://t.me/luckyhacker42 https://t.co/8KHIPaKMvA

    Post summary

    The tweet points to a Medium article that announces the discovery of a reflected XSS vulnerability (CVE‑2025‑0133) identified via Shodan reconnaissance. No evidence of active exploitation, PoC code, or patch information is provided.

    18065332.8K
    5.0K followersView on X
  • Md Nawshad Ahmmed@Nawshad_12
    Disclosure

    About Reflected Xss. (Reflected XSS Vulnerability in SSL VPN Endpoint - CVE-2025-0133) : https://mdnawshadahmmed.medium.com/i-got-reflected-xss-vulnerability-in-ssl-vpn-endpoint-cve-2025-0133-bugcrowd-public-program-ddcd2f37e1e4 #bugbounty #xss #vulnerable #vulnerability #owasp #WebSecurity

    Post summary

    The post announces a reflected XSS vulnerability (CVE-2025-0133) in an SSL VPN endpoint, linking to a Medium article for details.

    00022174
    116 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    PoC

    🚨 The 404 Blind Spot: Exploiting Reflected XSS in Error Handlers and What #CVE-2025-0133 Teaches Us About Modern Bug Bounty Hunting + Video https://undercodetesting.com/the-404-blind-spot-exploiting-reflected-xss-in-error-handlers-and-what-cve-2025-0133-teaches-us-about-modern-bug-bounty-hunting-video/ Educational Purposes!

    Post summary

    The post offers an educational walkthrough and video explaining how CVE‑2025‑0133 enables reflected XSS via error handlers, but it does not provide concrete code or mention active exploitation.

    0000065
    678 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    General

    🚨 #CVE-2025-0133: The 0 Reflected XSS That Could Hijack Your Session – Here’s How to Hunt and Harden Against It + Video https://undercodetesting.com/cve-2025-0133-the-0-reflected-xss-that-could-hijack-your-session-heres-how-to-hunt-and-harden-against-it-video/ Educational Purposes!

    Post summary

    The tweet links to a video that explains CVE-2025-0133, a reflected XSS vulnerability, and offers guidance on hunting and hardening, without providing exploitation proofs, active use evidence, or patch information.

    00000706
    497 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Disclosure

    🚨 The SSL #VPN XSS Ticking Time Bomb: How #CVE-2025-0133 Exposes Your Corporate Gateway + Video https://undercodetesting.com/the-ssl-vpn-xss-ticking-time-bomb-how-cve-2025-0133-exposes-your-corporate-gateway-video/ Educational Purposes!

    Post summary

    The post announces a disclosed XSS vulnerability (CVE-2025-0133) in SSL VPN, linking to a video demonstration, but offers no PoC, exploit code, patches, or evidence of active exploitation.

    0000065
    393 followersView on X

Explore more