An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software.
CVE ID: CVE-2025-0107
CVSS Base Severity: HIGH
CVSS Base Score: 7.7
Vendor: Palo Alto Networks
Product: Cloud NGFW
http/cves/2025/CVE-2025-0107.yaml
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 12.0% (scored less or equal to compared to others)
EPSS Date: 2025-02-21 (when was this score calculated)