CVE-2025-7382: Vulnerability in Sophos Sophos Firewall
A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achieving pre-auth code execution on High Availability (HA) auxiliary devices, if OTP authentication for the admin user is enabled.
CVE-2025-7382: Vulnerability in Sophos Sophos Firewall
Description
A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achieving pre-auth code execution on High Availability (HA) auxiliary devices, if OTP authentication for the admin user is enabled.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- Sophos
- Date Reserved
- 2025-07-09T09:26:15.788Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 687e4119a83201eaac0fbb9a
Added to database: 7/21/2025, 1:31:05 PM
Last updated: 7/21/2025, 1:31:05 PM
Views: 1
Related Threats
CVE-2025-7624: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Sophos Sophos Firewall
CriticalCVE-2025-6704: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Sophos Sophos Firewall
CriticalCVE-2025-7921: CWE-121 Stack-based Buffer Overflow in ASKEY RTF8207w
CriticalCVE-2025-25287: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in lakejason0 mediawiki-skins-Lakeus
MediumCVE-2025-30192: CWE-345 Insufficient Verification of Data Authenticity in PowerDNS Recursor
HighActions
External Links
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.