CVE-2025-7382
21.07.2025, 14:15
A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2)can lead to adjacent attackers achieving pre-auth code execution on High Availability (HA) auxiliary devices, if OTP authentication for the admin user is enabled.
| Vendor | Product | Version |
|---|---|---|
| sophos | firewall_firmware | 𝑥 < 21.0.2 |
𝑥
= Vulnerable software versions