PT-2025-30272 · Sophos · Sophos Firewall

CVE-2025-7382

·

Published

2025-07-21

·

Updated

2025-11-17

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sophos Firewall versions prior to 21.0 MR2 (21.0.2)
Description A command injection vulnerability exists in the WebAdmin component of Sophos Firewall. This issue can allow adjacent attackers to achieve pre-authentication code execution on High Availability (HA) auxiliary devices when One-Time Password (OTP) authentication is enabled for the admin user.
Recommendations Update Sophos Firewall to version 21.0 MR2 (21.0.2) or later.

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-10972
CVE-2025-7382

Affected Products

Sophos Firewall