CVE-2025-7382 Information
Jul 22, 2025
cve
Description
A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achieving pre-auth code execution on High Availability (HA) auxiliary devices if OTP authentication for the admin user is enabled.
Reference
https://www.sophos.com/en-us/security-advisories/sophos-sa-20250721-sfos-rce
Related CNNVD
CNNVD-202507-2646 (Published: 2025-07-21)
Share on: