Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/cybertechajju/cve-2025-5755
Vulnerability ScannersExploitationWeb Application ExploitationInformation GatheringPenetration TestingLearning & Education
GitHubcybertechajju/cve-2025-5755

cve-2025-5755

Asynchronous scanner and exploit tool for CVE-2025-5777 (CitrixBleed 2). Detects memory leaks in NetScaler ADC/Gateway, parses sensitive data like session cookies, and generates reports for authorized security testing.

View Repository
821 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-5777: The Ultimate PoC & Scanner 🚀

Hacker GIF

CVE Severity Author License

An advanced, powerful, and easy-to-use tool designed to detect and exploit CVE-2025-5777 (CitrixBleed 2). This script not only identifies the vulnerability but also helps in demonstrating its impact by parsing human-readable information from the memory leak.


What is CVE-2025-5777?

CVE-2025-5777 is a critical memory leak vulnerability in NetScaler (formerly Citrix) ADC and Gateway products. It allows an unauthenticated, remote attacker to read chunks of sensitive data from the server's memory, such as session cookies, usernames, passwords, and other private information.

A successful attack resulting in a session cookie leak can lead to a full Account Takeover, completely bypassing login credentials and multi-factor authentication (MFA).


✨ Features

  • High-Speed Asynchronous Scanning: Utilizes asyncio and aiohttp to scan multiple targets quickly and efficiently.
  • Intelligent Data Parsing: Automatically extracts human-readable strings from raw binary memory dumps.
  • Sensitive Data Detection: Automatically identifies and highlights high-impact patterns like session cookies (NSC_AAAC).
  • Comprehensive Reporting: Saves all findings to a clean leaks.txt file for easy analysis.

⚠️ Disclaimer

This tool is created for educational and authorized bug bounty purposes ONLY. Unauthorized use of this tool on any system is illegal. The developer is not responsible for any misuse or damage caused by this tool.


🎥 Video Tutorial: Finding & Exploiting

For a full, step-by-step guide on how to find and exploit vulnerabilities, I have created a detailed video. This video demonstrates the complete process, from identifying targets to executing the exploit.

Watch the full step-by-step video guide here: Live Hacking Demo: Finding and Exploiting a Critical Vulnerability


📚 Official References

  • NIST NVD: CVE-2025-5777 Detail
  • Citrix Support: CTX693420 Security Bulletin

🙏 Credits and Acknowledgements

  • Tool Developer & Researcher: CyberTechAjju
  • Original Vulnerability Research: The foundational research and original exploit concepts for this vulnerability were published by security researchers at Watchtwr Labs and others in the community. This tool builds upon their essential work.

📜 License

This project is licensed under the MIT License. See the LICENSE file for more details.

Download Tool