High severity7.2NVD Advisory· Published Oct 9, 2025· Updated Apr 1, 2026
CVE-2025-4615
CVE-2025-4615
Description
An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands.
The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.
Cloud NGFW and Prisma® Access are not affected by this vulnerability.
Affected products
2cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*range: >=10.2.0,<10.2.17
- (no CPE)
Patches
Vulnerability mechanics
References
1- security.paloaltonetworks.com/CVEN-2025-4615nvdVendor Advisory
News mentions
0No linked articles in our index yet.