A critical vulnerability, CVE-2025-0108, has been identified in Palo Alto Networks PAN-OS, affecting versions 10.1.0 through 10.1.14, 10.2.0 through 10.2.13, 11.1.0 through 11.1.6, and 11.2.0 through 11.2.4. This vulnerability arises from an authentication bypass that allows an unauthenticated attacker with network access to the management web interface to circumvent authentication controls and invoke specific PHP scripts. While this flaw does not directly enable remote code execution (RCE), it significantly impacts the integrity and confidentiality of PAN-OS by exposing sensitive administrative functions.
The IONIX research team developed and tested an exploit simulation on relevant assets to verify the vulnerability’s impact and assess potential exposure. The findings are detailed in this post. Palo Alto Networks has released upgrade addressing this vulnerability. Organizations are advised to upgrade to the latest versions to mitigate potential risks.
References:

