Loading
Generated remediation guidance and an executive summary. No account required.
An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software.
Use CWE-78, Paloaltonetworks vendor hub and Expedition product page to widen CVE-2025-0107 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-9463, CVE-2024-5910 and CVE-2024-9465 for nearby disclosures in the same product family.