← Back to browse · API

CVE-2025-0107

Severity
HIGH
CVSS
7.7
EPSS
0.78532
Risk score
58.29
CISA KEV
No
PoC
No
Published
2025-01-11
Modified
2025-01-24
First seen
2026-08-07
Aliases
EUVD-2025-1504, GHSA-MHJ4-9938-5FPW
Products
Palo Alto Networks:Expedition 1 <1.2.100
Sources
euvd EUVD-2025-1504

Description

An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software.

References