CVE-2025-7382 Information

Description

A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achieving pre-auth code execution on High Availability (HA) auxiliary devices if OTP authentication for the admin user is enabled.

Reference

https://www.sophos.com/en-us/security-advisories/sophos-sa-20250721-sfos-rce

CNNVD-202507-2646 (Published: 2025-07-21)

Share on: