CVE-2025-0107: Expedition: OS Command Injection Vulnerability
An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0107?
CVE-2025-0107 is classified as a high-severity vulnerability due to its potential for unauthorized access and data disclosure.
How do I fix CVE-2025-0107?
To remediate CVE-2025-0107, update Palo Alto Networks Expedition to the latest version where the vulnerability has been patched.
What are the potential impacts of CVE-2025-0107?
Exploitation of CVE-2025-0107 can lead to the disclosure of sensitive information such as usernames, cleartext passwords, and device API keys.
Who is affected by CVE-2025-0107?
CVE-2025-0107 affects users of Palo Alto Networks Expedition, particularly those who have not implemented the latest security updates.
Is CVE-2025-0107 an authenticated or unauthenticated vulnerability?
CVE-2025-0107 is an unauthenticated vulnerability, allowing attackers to exploit it without needing any valid credentials.