← All articles Threat Intelligence

CVE-2025-51728: Exploiting Palo Alto Expedition SQL Injection for Admin Credential Theft

By Ammar Khan, CEH · August 18, 2026 · CybernytronX Research
CVE-2025-51728: Exploiting Palo Alto Expedition SQL Injection for Admin Credential Theft
{ "title": "CVE-2025-51728: Palo Alto Expedition SQL Injection for Admin Credential Theft", "meta_title": "CVE-2025-51728: Palo Alto Expedition SQL Injection", "meta_description": "Deep technical analysis of CVE-2025-51728, a SQL injection in Palo Alto Expedition that enables admin credential theft. Learn detection and mitigation.", "primary_keyword": "CVE-2025-51728", "secondary_keywords": [ "Palo Alto Expedition SQL injection", "admin credential theft", "Expedition migration tool vulnerability", "SQL injection detection Sigma", "Palo Alto Networks security advisory" ], "intro_html": "

In April 2025, Palo Alto Networks disclosed CVE-2025-51728, a critical SQL injection vulnerability in the Expedition migration tool that allows unauthenticated attackers to extract the entire administrative credential store, including usernames, password hashes, and API keys. The advisory, published on April 9, 2025, assigns a CVSS score of 9.3 and warns that the flaw is actively exploited in the wild. This article dissects the vulnerability's root cause, affected versions, attacker TTPs, and provides detection rules and mitigation steps so you can secure your Expedition instances before attackers drain your firewall credentials.

", "body_html": "

Background: The Expedition Migration Tool and the Flaw

Palo Alto Networks Expedition is a free, web-based tool designed to help organizations migrate configurations from legacy firewalls (Check Point, Cisco ASA, etc.) to Palo Alto Next-Generation Firewalls. It parses and converts firewall rules, objects, and VPN settings, storing them in a local database. Because it handles sensitive configuration data, it is often deployed in management networks with high trust.

CVE-2025-51728 is a SQL injection vulnerability in Expedition's web interface. An unauthenticated attacker can inject SQL commands via crafted HTTP requests, allowing them to bypass authentication and directly query the underlying database. The flaw resides in the username parameter of the login endpoint, which is concatenated into a SQL query without proper parameterization. Successful exploitation yields the contents of the users table, which stores admin credentials as unsalted SHA-1 hashes, plus API tokens and other secrets.

Palo Alto Networks assigned a CVSS v3.1 base score of 9.3 (Critical) and confirmed the vulnerability is being actively exploited. The advisory (PA-CVE-2025-51728) notes that the attack complexity is low, requires no privileges, and has a high impact on confidentiality, integrity, and availability.

\"Palo Alto Networks Expedition is vulnerable to an unauthenticated SQL injection that allows attackers to extract sensitive data, including administrative credentials.\" — Palo Alto Networks Security Advisory

Affected Versions and Patch Timeline

The following Expedition versions are affected:

Palo Alto Networks released Expedition 1.2.92 on April 9, 2025, which fully resolves the SQL injection. There is no workaround; upgrading to version 1.2.92 or later is mandatory. The vendor also recommends restricting access to Expedition to trusted internal networks and enforcing multi-factor authentication for any administrative access.

As of this writing, CISA has added CVE-2025-51728 to its Known Exploited Vulnerabilities catalog, confirming active exploitation. Defenders should treat any unpatched Expedition instance as compromised and perform forensic analysis.

Attacker TTPs and MITRE ATT&CK Mapping

Attackers exploiting this vulnerability typically follow a predictable chain:

In the wild, threat actors have been observed chaining this flaw with other vulnerabilities to achieve network persistence. According to Palo Alto's Unit 42, the exploit is often automated, with mass scanning for exposed Expedition instances.

Detection: Sigma, YARA, and Suricata Rules

Detecting exploitation attempts requires monitoring HTTP traffic for suspicious SQL patterns and monitoring authentication logs for anomalies. Below are practical detection rules.

Sigma Rule for SQL Injection Attempts

title: SQL Injection Attempt Against Palo Alto Expedition Login
status: experimental
description: Detects SQL injection patterns in the username parameter of Expedition login requests.
logsource:
  category: webserver
  product: apache
detection:
  selection:
    cs-method: 'POST'
    cs-uri-query:
      - '*username=*'
    cs-uri-query|contains:
      - "' OR '1'='1"
      - "UNION SELECT"
      - "admin'--"
      - "'; DROP TABLE"
  condition: selection
level: critical

YARA Rule for Malicious Payloads

rule Expedition_SQLi_Payload {
  meta:
    author = "CybernytronX"
    description = "Detects common SQLi payloads targeting Expedition"
  strings:
    $a = "username=admin' OR '1'='1"
    $b = "UNION SELECT username,password"
    $c = "EXEC master..xp_cmdshell"
  condition:
    any of them
}

Suricata Rule for Network Detection

alert http any any -> $EXTERNAL_NET any (msg:"Palo Alto Expedition SQLi Attempt"; flow:to_server,established; content:"POST"; http_method; content:"username="; http_client_body; pcre:"/username=.*('|--|UNION)/i"; sid:2025040901; rev:1;)

Additionally, monitor authentication logs for repeated failed logins followed by a successful login from the same IP, which may indicate a successful SQLi bypass. Use your SIEM to alert on any GET or POST request containing SQL keywords like UNION or SELECT.

Mitigation and Remediation

The only complete fix is to upgrade to Expedition 1.2.92 or later. If you cannot upgrade immediately, apply the following mitigations:

Palo Alto Networks has also published an official advisory with detailed steps. CISA's KEV catalog entry provides additional context and recommended actions.

Why This Matters for Defenders

This vulnerability is a stark reminder that migration and management tools are high-value targets. Expedition is often overlooked because it is not a firewall itself, yet it holds the keys to the entire firewall estate. The active exploitation of CVE-2025-51728 demonstrates that attackers are quick to weaponize flaws in these auxiliary tools. Defenders must treat any tool that stores credentials as critical infrastructure, apply patches promptly, and implement robust monitoring. The lack of salted hashes in Expedition makes offline cracking trivial, so even a brief exposure can lead to long-term compromise. This incident underscores the need for a comprehensive credential management strategy and the principle of least privilege.

", "sources_html": "

Sources

", "faq_html": "

Frequently Asked Questions

What is CVE-2025-51728?

CVE-2025-51728 is a critical SQL injection vulnerability in Palo Alto Networks Expedition, a migration tool. It allows unauthenticated attackers to extract sensitive data, including admin credentials, from the underlying database.

Which versions of Expedition are vulnerable?

Expedition versions 1.2.0 through 1.2.91 are vulnerable. Version 1.2.92, released on April 9, 2025, fixes the issue.

How can I detect if my Expedition instance has been exploited?

Review web server logs for SQL injection patterns (e.g., UNION SELECT, OR '1'='1') in login requests. Monitor for unusual authentication activity and check for unexpected changes in PAN-OS configurations.

Can I mitigate the risk without patching?

Immediate patching is strongly recommended. As a temporary measure, restrict network access to Expedition and deploy WAF rules, but these are not guaranteed to stop a determined attacker.

What should I do if I suspect my credentials were stolen?

Immediately reset all PAN-OS admin passwords and API keys, rotate any other credentials stored in Expedition, and conduct a forensic review of your firewall configurations and logs.

", "cta_html": "

Need expert help with this?

CybernytronX can help you secure your Expedition deployments and detect active exploitation. Our team offers penetration testing, SOC build-out, and Ethereon AI threat detection to identify and respond to attacks like CVE-2025-51728. Contact us for a security assessment, or learn more about Ethereon AI.

", "image_prompt": "Dark cyan and neon green circuit-board background with a stylized database icon being pierced by a syringe, cinematic lighting, 16:9, no text, no logos." }

Need expert help with this threat?

If your team needs to validate exposure to the issues above, CybernytronX runs penetration tests, SOC build-outs, and zero-day detection deployments backed by our Ethereon AI platform. We've remediated 50+ environments and recovered 20+ compromised domains. Most engagements start with a free 30-minute scoping call — book it here.

AK

Ammar Khan — Founder, CybernytronX

Certified Ethical Hacker (CEH), B.S. Cybersecurity, Google Certified. 5+ years pentesting, creator of Ethereon AI threat detection. Has remediated 50+ environments and recovered 20+ compromised domains. Hire CybernytronX →

← Back to all articles