A vulnerability in the Palo Alto Networks PAN-OS management interface, tracked as CVE-2025-0108 and internally as PAN-273971, permits unauthenticated access to the Zero Touch Provisioning endpoint at /php/ztp_gate.php. The flaw stems from inconsistent URL decoding and path normalization between the Nginx reverse proxy and Apache mod_rewrite: Nginx can classify a crafted double-encoded traversal request as unauthenticated while Apache resolves it to a protected PHP resource.
The issue was identified while examining fixes for the previously exploited PAN-OS vulnerabilities CVE-2024-0012 and CVE-2024-9474. Palo Alto Networks remediated the flaw in PAN-OS 10.2.14, 11.0.7, 11.2.5, and later releases; organizations should update affected firewalls and restrict management-interface access through IP allowlisting.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks tracked the authentication-bypass issue as PAN-273971 and fixed it in PAN-OS 10.2.14, 11.0.7, 11.2.5, and later versions. The company recommended IP allowlisting access to the management interface to reduce exposure.
Assetnote identified a full authentication bypass in the Palo Alto Networks PAN-OS management interface, caused by inconsistent URL decoding and path handling between Nginx and Apache/mod_rewrite. A double-encoded traversal request could reach and execute the Zero Touch Provisioning endpoint /php/ztp_gate.php without authentication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.