CVE-2025-0107
An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software.
Vendor
Product
CWE
Yayın Tarihi
2025-01-11 03:15:22
Güncelleme
2026-01-23 21:50:52
Source Identifier
psirt@paloaltonetworks.com
KEV Date Added
-