← Back to CVE List

CVE-2025-0107

Published: 2025-01-11T03:15Z
Last Modified: 2025-01-15T23:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt