🔴 CVE-2025-0108

Authentication bypass vulnerability in Palo Alto Networks PAN-OS management web interface allows unauthenticated attackers to bypass authentication and invoke PHP scripts that can compromise firewall integrity and confidentiality. This vulnerability is actively exploited in the wild and listed in CISA KEV catalog.

← Back to Overview
HIGH_RISK
Risk Level
8.8
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2025-02-12

Added to CISA KEV: 2025-02-18 6 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-06-04)

CVE-2025-0108 is a critical authentication bypass vulnerability affecting Palo Alto Networks PAN-OS software [1].

Overview and Impact
  • Vulnerability Type: Authentication bypass in the management web interface [3].
  • Impact: Successful exploitation allows an unauthenticated attacker to bypass authentication requirements and invoke specific PHP scripts on the affected device [4].
  • Exploitation Context: Palo Alto Networks has observed this vulnerability being used in active, chained attacks against unpatched and unsecured PAN-OS web management interfaces [1].
Attack Method and Requirements
  • Network vs. Local: The attack is network-based; it requires the attacker to have network access to the management web interface [3].
  • User Interaction: No user interaction is required for a successful exploit [5].
  • Chained Exploitation: Threat actors have been observed chaining CVE-2025-0108 with other vulnerabilities—specifically CVE-2024-9474 (a privilege escalation flaw) and CVE-2025-0111 (an authenticated file read vulnerability)—to gain unauthorized access and breach PAN-OS firewalls [2].
Mitigation and Status
  • Patch Status: Users are advised to refer to the official Palo Alto Networks security advisory for specific patch information and to apply updates as part of their regular maintenance cycle [1].
  • Immediate Mitigation: Palo Alto Networks recommends significantly reducing the risk of exploitation by restricting access to the management interface. Ideally, access should be limited to a dedicated, secure jump box, ensuring that only authorized systems can reach the interface [1].

Sources

  1. CVE-2025-0108 PAN-OS: Authentication Bypass in the ...

    Palo Alto Networks Security Advisory: CVE-2025-0108 PAN-OS: Authentication Bypass in the Management Web Interface An authentication bypass ... Exploitation Status Palo Alto Networks has observed exploit attempts chaining CVE-2025-0108 with CVE-2024-9474 and CVE-2025-0111 on unpatched and unsecured P…

  2. CVE-2025-25067 | CyberSecurityBoard

    Palo Alto Networks tags new firewall bug as exploited in attacks - Palo Alto Networks warns that a file read vulnerability (CVE-2025-0111) is now being chained in attacks with two other flaws (CVE-2025-0108 with CVE-2024-9474) to breach PAN-OS firewalls in active attacks. ... attackers making exploi…

  3. CVE‑2025‑0108 Detail - NVD

    An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface.

  4. NVD - CVE-2025-0108

    CVE-2025-0108 Detail Description An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP sc…

  5. CVE-2025-0108 - Vulnerability Details - OpenCVE

    Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected). ... Attack Requirements Present. User Interaction None. Vulnerable System Confidentiality Impact High.chaining CVE-2025-0108 with CVE-2024-9474 and CVE-2025-0111 on unpatched and u…