ZeroHour

CVE-2025-0107

moderate

Unauthenticated OS Command Injection in Palo Alto Networks Expedition

CVSS 4.0
7.7 high
EPSS
79%p100
Published
()
Modified
AI analysis

CVE-2025-0107 is an unauthenticated OS command injection flaw (CWE-78) in Palo Alto Networks Expedition, the vendor's migration and assessment tool for PAN-OS firewalls. A remote attacker with no credentials or user interaction can send a crafted request to the Expedition web interface and execute arbitrary operating system commands as the www-data user. Because Expedition stores migration and management data, the attacker gains access to usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software that Expedition manages. Only organizations running Expedition — typically those performing PAN-OS migrations or bulk assessments — are affected; organizations running only PAN-OS firewalls without Expedition are not directly exposed. As of the current data there is no public proof-of-concept and the flaw is not yet in CISA's Known Exploited Vulnerabilities catalog, but EPSS assigns a 78.5% probability of exploitation within 30 days (100th percentile), indicating an elevated near-term risk.

What to do: Update Expedition to the latest patched release per the Palo Alto Networks advisory, and restrict the Expedition web interface to trusted management networks or VPN access. Because the flaw can expose stored PAN-OS credentials, configurations, and API keys, review Expedition logs for unexpected www-data command activity and rotate affected firewall passwords and API keys once patched.

Affected
Palo Alto Networks Expedition
Estimated exposure
moderatelikely on the order of 1,000–10,000 internet-exposed Expedition instances (estimate) — Expedition is a specialized migration/assessment tool deployed only by a subset of Palo Alto Networks customers rather than on every PAN-OS firewall, and only some of those deployments have the web interface exposed to the internet, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software.

Vendors
paloaltonetworks
Products
expedition
Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Green

In the news