VYPR
High severity7.2NVD Advisory· Published Oct 9, 2025· Updated Apr 1, 2026

CVE-2025-4615

CVE-2025-4615

Description

An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands.

The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.

Cloud NGFW and Prisma® Access are not affected by this vulnerability.

Affected products

2
  • cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*range: >=10.2.0,<10.2.17
    • (no CPE)

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.