CVE-2025-0107
Expedition: OS Command Injection Vulnerability
Record summary
CVE-2025-0107 has a selected CVSS score of 7.7 (high); EIP currently links 1 Nuclei template.
Description
An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 25, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 23, 2025 · Source: CVE List
Affected products and versions
5| Product | Source | Version range | Status |
|---|---|---|---|
Cloud NGFWBrowse Palo Alto Networks / Cloud NGFWDefault status: unaffected | CVE List | All versions | unaffected |
ExpeditionBrowse Palo Alto Networks / ExpeditionDefault status: unaffected | VulnCheck, CVE List | 1 to < 1.2.100 | affected |
Default status: unaffected | CVE List | All versions | unaffected |
Default status: unaffected | CVE List | All versions | unaffected |
Prisma AccessBrowse Palo Alto Networks / Prisma AccessDefault status: unaffected | CVE List | All versions | unaffected |
Nuclei templates
1ProjectDiscoveryCRITICALPalo Alto Networks Expedition - OS Command InjectionCVSS 9.8
An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software.
Impact
Unauthenticated attackers can execute arbitrary OS commands on Palo Alto Networks Expedition servers, leading to disclosure of sensitive firewall credentials, configurations, and API keys that could compromise all connected PAN-OS firewalls.
Remediation
Upgrade to the latest patched version of Palo Alto Networks Expedition as specified in the vendor security advisory.
Source: ProjectDiscovery