CVE-2025-6704 Information

Description

An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to pre-auth remote code execution if a specific configuration of SPX is enabled in combination with the firewall running in High Availability (HA) mode.

Reference

https://www.sophos.com/en-us/security-advisories/sophos-sa-20250721-sfos-rce

CNNVD-202507-2645 (Published: 2025-07-21)

Share on: