CVE-2025-7624
EUVD-2025-2208521.07.2025, 14:15
An SQL injection vulnerability in the legacy (transparent) SMTP proxy of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to remote code execution, if a quarantining policy is active for Email and SFOS was upgraded from a version older than 21.0 GA.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| sophos | firewall_firmware | 𝑥 < 21.0.2 |
𝑥
= Vulnerable software versions