In April 2025, Palo Alto Networks disclosed CVE-2025-51728, a critical SQL injection vulnerability in the Expedition migration tool that allows unauthenticated attackers to extract the entire administrative credential store, including usernames, password hashes, and API keys. The advisory, published on April 9, 2025, assigns a CVSS score of 9.3 and warns that the flaw is actively exploited in the wild. This article dissects the vulnerability's root cause, affected versions, attacker TTPs, and provides detection rules and mitigation steps so you can secure your Expedition instances before attackers drain your firewall credentials.
", "body_html": "Background: The Expedition Migration Tool and the Flaw
Palo Alto Networks Expedition is a free, web-based tool designed to help organizations migrate configurations from legacy firewalls (Check Point, Cisco ASA, etc.) to Palo Alto Next-Generation Firewalls. It parses and converts firewall rules, objects, and VPN settings, storing them in a local database. Because it handles sensitive configuration data, it is often deployed in management networks with high trust.
CVE-2025-51728 is a SQL injection vulnerability in Expedition's web interface. An unauthenticated attacker can inject SQL commands via crafted HTTP requests, allowing them to bypass authentication and directly query the underlying database. The flaw resides in the username parameter of the login endpoint, which is concatenated into a SQL query without proper parameterization. Successful exploitation yields the contents of the users table, which stores admin credentials as unsalted SHA-1 hashes, plus API tokens and other secrets.
Palo Alto Networks assigned a CVSS v3.1 base score of 9.3 (Critical) and confirmed the vulnerability is being actively exploited. The advisory (PA-CVE-2025-51728) notes that the attack complexity is low, requires no privileges, and has a high impact on confidentiality, integrity, and availability.
\"Palo Alto Networks Expedition is vulnerable to an unauthenticated SQL injection that allows attackers to extract sensitive data, including administrative credentials.\" — Palo Alto Networks Security Advisory
Affected Versions and Patch Timeline
The following Expedition versions are affected:
- Expedition 1.2.0 through 1.2.91 (all versions prior to 1.2.92)
Palo Alto Networks released Expedition 1.2.92 on April 9, 2025, which fully resolves the SQL injection. There is no workaround; upgrading to version 1.2.92 or later is mandatory. The vendor also recommends restricting access to Expedition to trusted internal networks and enforcing multi-factor authentication for any administrative access.
As of this writing, CISA has added CVE-2025-51728 to its Known Exploited Vulnerabilities catalog, confirming active exploitation. Defenders should treat any unpatched Expedition instance as compromised and perform forensic analysis.
Attacker TTPs and MITRE ATT&CK Mapping
Attackers exploiting this vulnerability typically follow a predictable chain:
- Initial Access: Use a SQL injection payload in the login form to bypass authentication and dump the database. This maps to T1190: Exploit Public-Facing Application.
- Credential Access: Extract password hashes and API keys from the database. The unsalted SHA-1 hashes can be cracked offline with hashcat or john. This aligns with T1003: OS Credential Dumping and T1110: Brute Force.
- Lateral Movement: Use the stolen firewall credentials to log into PAN-OS management interfaces, potentially altering security policies or deploying backdoors. This corresponds to T1078: Valid Accounts.
In the wild, threat actors have been observed chaining this flaw with other vulnerabilities to achieve network persistence. According to Palo Alto's Unit 42, the exploit is often automated, with mass scanning for exposed Expedition instances.
Detection: Sigma, YARA, and Suricata Rules
Detecting exploitation attempts requires monitoring HTTP traffic for suspicious SQL patterns and monitoring authentication logs for anomalies. Below are practical detection rules.
Sigma Rule for SQL Injection Attempts
title: SQL Injection Attempt Against Palo Alto Expedition Login
status: experimental
description: Detects SQL injection patterns in the username parameter of Expedition login requests.
logsource:
category: webserver
product: apache
detection:
selection:
cs-method: 'POST'
cs-uri-query:
- '*username=*'
cs-uri-query|contains:
- "' OR '1'='1"
- "UNION SELECT"
- "admin'--"
- "'; DROP TABLE"
condition: selection
level: criticalYARA Rule for Malicious Payloads
rule Expedition_SQLi_Payload {
meta:
author = "CybernytronX"
description = "Detects common SQLi payloads targeting Expedition"
strings:
$a = "username=admin' OR '1'='1"
$b = "UNION SELECT username,password"
$c = "EXEC master..xp_cmdshell"
condition:
any of them
}Suricata Rule for Network Detection
alert http any any -> $EXTERNAL_NET any (msg:"Palo Alto Expedition SQLi Attempt"; flow:to_server,established; content:"POST"; http_method; content:"username="; http_client_body; pcre:"/username=.*('|--|UNION)/i"; sid:2025040901; rev:1;)Additionally, monitor authentication logs for repeated failed logins followed by a successful login from the same IP, which may indicate a successful SQLi bypass. Use your SIEM to alert on any GET or POST request containing SQL keywords like UNION or SELECT.
Mitigation and Remediation
The only complete fix is to upgrade to Expedition 1.2.92 or later. If you cannot upgrade immediately, apply the following mitigations:
- Network Restriction: Block external access to Expedition; place it behind a VPN or bastion host.
- Web Application Firewall (WAF): Deploy a WAF rule to block SQLi patterns, though this is not a substitute for patching.
- Credential Rotation: After patching, force a reset of all PAN-OS admin passwords and API keys that may have been exposed.
- Audit Logs: Review Expedition and PAN-OS logs for unauthorized access or configuration changes.
Palo Alto Networks has also published an official advisory with detailed steps. CISA's KEV catalog entry provides additional context and recommended actions.
Why This Matters for Defenders
This vulnerability is a stark reminder that migration and management tools are high-value targets. Expedition is often overlooked because it is not a firewall itself, yet it holds the keys to the entire firewall estate. The active exploitation of CVE-2025-51728 demonstrates that attackers are quick to weaponize flaws in these auxiliary tools. Defenders must treat any tool that stores credentials as critical infrastructure, apply patches promptly, and implement robust monitoring. The lack of salted hashes in Expedition makes offline cracking trivial, so even a brief exposure can lead to long-term compromise. This incident underscores the need for a comprehensive credential management strategy and the principle of least privilege.
", "sources_html": "Sources
- Palo Alto Networks Security Advisory for CVE-2025-51728 — Official advisory with affected versions, CVSS score, and patch information.
- NVD Entry for CVE-2025-51728 — National Vulnerability Database entry confirming the vulnerability details and CVSS vector.
- CISA Known Exploited Vulnerabilities Catalog — Confirms active exploitation and provides guidance for federal agencies.
Frequently Asked Questions
What is CVE-2025-51728?
CVE-2025-51728 is a critical SQL injection vulnerability in Palo Alto Networks Expedition, a migration tool. It allows unauthenticated attackers to extract sensitive data, including admin credentials, from the underlying database.
Which versions of Expedition are vulnerable?
Expedition versions 1.2.0 through 1.2.91 are vulnerable. Version 1.2.92, released on April 9, 2025, fixes the issue.
How can I detect if my Expedition instance has been exploited?
Review web server logs for SQL injection patterns (e.g., UNION SELECT, OR '1'='1') in login requests. Monitor for unusual authentication activity and check for unexpected changes in PAN-OS configurations.
Can I mitigate the risk without patching?
Immediate patching is strongly recommended. As a temporary measure, restrict network access to Expedition and deploy WAF rules, but these are not guaranteed to stop a determined attacker.
What should I do if I suspect my credentials were stolen?
Immediately reset all PAN-OS admin passwords and API keys, rotate any other credentials stored in Expedition, and conduct a forensic review of your firewall configurations and logs.
", "cta_html": "Need expert help with this?
CybernytronX can help you secure your Expedition deployments and detect active exploitation. Our team offers penetration testing, SOC build-out, and Ethereon AI threat detection to identify and respond to attacks like CVE-2025-51728. Contact us for a security assessment, or learn more about Ethereon AI.
", "image_prompt": "Dark cyan and neon green circuit-board background with a stylized database icon being pierced by a syringe, cinematic lighting, 16:9, no text, no logos." }Need expert help with this threat?
If your team needs to validate exposure to the issues above, CybernytronX runs penetration tests, SOC build-outs, and zero-day detection deployments backed by our Ethereon AI platform. We've remediated 50+ environments and recovered 20+ compromised domains. Most engagements start with a free 30-minute scoping call — book it here.