CVE-2025-0108CRITICAL 9.1CISA KEVEPSS p99.9%

CVE-2025-0108Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

Palo Alto Networks / PAN-OS

Description

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in its management web interface. This vulnerability allows an unauthenticated attacker with network access to the management web interface to bypass the authentication normally required and invoke certain PHP scripts.

Scoring

CVSS 3.19.1 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS98.34% probability of exploitation · percentile 99.9% · 2026-06-17T12:03:21Z
Published2025-02-12
Last modified2025-11-04

CISA KEV entry

Added to KEV: 2025-02-18

Underlying weaknesses· 1

CWE-306

References

  1. https://security.paloaltonetworks.com/CVE-2025-0108
  2. https://github.com/iSee857/CVE-2025-0108-PoC
  3. https://slcyber.io/blog/nginx-apache-path-confusion-to-auth-bypass-in-pan-os/
  4. https://www.bleepingcomputer.com/news/security/palo-alto-networks-tags-new-firewall-bug-as-exploited-in-attacks/
  5. https://www.darkreading.com/remote-workforce/patch-now-cisa-researchers-warn-palo-alto-flaw-exploited-wild
  6. https://www.securityweek.com/palo-alto-networks-confirms-exploitation-of-firewall-vulnerability/
  7. https://www.theregister.com/2025/02/19/palo_alto_firewall_attack/
  8. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-0108

1

TypeTargetConfidenceTier
WeaknessMissing Authentication for Critical Functioncwe-3060%live

(incoming)1

TypeTargetConfidenceTier
KEVEntryPalo Alto Networks PAN-OS Authentication Bypass Vulnerabilitykev-cve-2025-01080%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability
CVE
Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability
CVE
CVE-2025-0107
CVE
CVE-2026-0265
CVE
Palo Alto Networks PAN-OS File Read Vulnerability
CVE
Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.