Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-0108

97
FAUCET Score

CVE-2025-0108 is a critical authentication bypass vulnerability in Palo Alto Networks PAN-OS software, affecting the management web interface. An unauthenticated attacker with network access can bypass authentication to invoke certain PHP scripts, potentially impacting the integrity and confidentiality of PAN-OS. This vulnerability has a CVSS score of 9.1 (CRITICAL) due to its network attack vector, low complexity, and high impact on confidentiality and integrity. It is actively exploited in the wild, as confirmed by its inclusion in the KEV catalog and high EPSS score, and has garnered significant community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 10.1.0, < 10.1.14CPE matchmatch criteria
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
>= 10.2.0, < 10.2.7CPE matchmatch criteria
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
>= 11.1.0, < 11.1.2CPE matchmatch criteria
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
>= 11.2.0, < 11.2.4CPE matchmatch criteria
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
10.1.14CPE matchmatch criteria
cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:-:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.8HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Red

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
98.45%
Probability of exploitation in next 30 days
EPSS Percentile
99.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Feb 18, 2025
Nuclei: CVE-2025-0108 · Feb 13, 2025
This CVE's current EPSS score of 0.9846 is in the 99th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

paloaltovendor investigatingvia nvd_reference
View patch

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
github.com / iSee857/CVE-2025-0108-PoC
ExploitThird Party Advisory
slcyber.io / blog/nginx-apache-path-confusion-to-auth-bypass-in-pan-os
ExploitPress/Media Coverage
bleepingcomputer.com / news/security/palo-alto-networks-tags-new-firewall-bug-as-exploited-in-attacks
Press/Media CoverageThird Party Advisory
darkreading.com / remote-workforce/patch-now-cisa-researchers-warn-palo-alto-flaw-exploited-wild
Press/Media CoverageThird Party Advisory
securityweek.com / palo-alto-networks-confirms-exploitation-of-firewall-vulnerability
Press/Media CoverageThird Party Advisory
theregister.com / 2025/02/19/palo_alto_firewall_attack
Press/Media CoverageThird Party Advisory
security.paloaltonetworks.com / CVE-2025-0108
ExploitVendor Advisory