Files
CVEs-PoC/2025/CVE-2025-0107.md
T
2025-09-29 21:09:30 +02:00

1.3 KiB

CVE-2025-0107

Description

An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software.

POC

Reference

No PoCs from references.

Github