CVE-2025-7624 Information

Description

An SQL injection vulnerability in the legacy (transparent) SMTP proxy of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to remote code execution if a quarantining policy is active for Email and SFOS was upgraded from a version older than 21.0 GA.

Reference

https://www.sophos.com/en-us/security-advisories/sophos-sa-20250721-sfos-rce

CNNVD-202507-2647 (Published: 2025-07-21)

Share on: