CVE-2025-0107: Palo Alto Networks Expedition

Critical severity, CVSS 9.8. EPSS: 78.5% chance of exploitation in the next 30 days.

An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software.

Affected products

Published 2025-01-11. Last modified 2026-06-17.