CVE-2025-0133

MEDIUMNVD 2.74.4
EchelonGraph scoreHIGH confidence

Score elevated to 4.4 because EPSS predicts 45% probability of exploitation within the next 30 days (top 1.3% of all CVEs). NVD baseline CVSS 2.7 retained for reference. Confidence: see factors.

Triggered by: EPSS exploit prediction ≥85%
Sources: epss, nvd
Elevated
4.4EG
EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
  • Lower severity and no public exploit yet
CISA-KEV: Not listedEPSS PROB: 46%CVSS: 2.7Exploit: Elevated riskExposed: 0

No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.

A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Networks PAN-OS® software enables execution of malicious JavaScript in the context of an authenticated Captive Portal user's browser when they click on a specially crafted link. The primary risk is phishing attacks that can lead to credential theft—particularly if you enabled Clientless VPN.

There is no availability impact to GlobalProtect features or GlobalProtect users. Attackers cannot use this vulnerability to tamper with or modify contents or configurations of the GlobalProtect portal or gateways. The integrity impact of this vulnerability is limited to enabling an attacker to create phishing and credential-stealing links that appear to be hosted on the GlobalProtect portal.

For GlobalProtect users with Clientless VPN enabled, there is a limited impact on confidentiality due to inherent risks of Clientless VPN that facilitate credential theft. You can read more about this risk in the informational bulletin PAN-SA-2025-0005 https://security.paloaltonetworks.com/PAN-SA-2025-0005 https://security.paloaltonetworks.com/PAN-SA-2025-0005 . There is no impact to confidentiality for GlobalProtect users if you did not enable (or you disable) Clientless VPN.

CVSS v3
2.7
EG Score
4.4(high)
EG Risk
38(Track)
EG Risk 38/100SSVC: Track

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity44% × 45%
Exploitation45% × 40%
Automatability0% × 15%
Action: Routine — remediate on your standard cadence.
EPSS PROB
46%
EPSS %ILE
99%
KEV
Not listed

Published

May 14, 2025

Last Modified

April 15, 2026

References (1)

Related CVEs are temporarily unavailable — the same-product, same-vendor and same-CWE lists could not be loaded just now. That is not a sign that none exist; please retry shortly.

Frequently asked(5)

What is CVE-2025-0133?
CVE-2025-0133 is a medium vulnerability published on May 14, 2025. A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Networks PAN-OS® software enables execution of malicious JavaScript in the context of an authenticated Captive Portal user's browser when they click on a specially crafted link. The…
When was CVE-2025-0133 disclosed?
CVE-2025-0133 was first published in the National Vulnerability Database on May 14, 2025, with the most recent update on April 15, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2025-0133 actively exploited?
CVE-2025-0133 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 46% probability of exploitation in the next 30 days, which ranks it in the top 1.2% of all scored CVEs.
What is the CVSS score of CVE-2025-0133?
CVE-2025-0133 has a CVSS v3 base score of 2.7 (NVD). EchelonGraph synthesises NVD + CISA KEV + FIRST EPSS + GHSA into a combined EG score of 4.4.
How do I remediate CVE-2025-0133?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2025-0133, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2025-0133

Explore →

Is Your Infrastructure Affected by CVE-2025-0133?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.