PT-2025-30272 · Sophos · Sophos Firewall

Published

2025-07-21

·

Updated

2025-11-17

·

CVE-2025-7382

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sophos Firewall versions prior to 21.0 MR2 (21.0.2)
Description A command injection vulnerability exists in the WebAdmin component of Sophos Firewall. This issue can allow adjacent attackers to achieve pre-authentication code execution on High Availability (HA) auxiliary devices when One-Time Password (OTP) authentication is enabled for the admin user.
Recommendations Update Sophos Firewall to version 21.0 MR2 (21.0.2) or later.

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-10972
CVE-2025-7382

Affected Products

Sophos Firewall