CVE-2025-7382 Details
Description
A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achieving pre-auth code execution on High Availability (HA) auxiliary devices, if OTP authentication for the admin user is enabled.
A command injection vulnerability has been identified in the WebAdmin interface of Sophos Firewall. This vulnerability affects versions prior to 21.0 MR2 (21.0.2) and allows adjacent attackers to execute code on High Availability (HA) auxiliary devices without authentication, provided that One-Time Password (OTP) authentication is enabled for the admin user.
Users should upgrade to Sophos Firewall version 21.0 MR2 or later. Hotfixes for this vulnerability have been released for several supported versions. Instructions for verifying the hotfix can be found in the Sophos Knowledge Base.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.sophos.com/en-us/security-advisories/sophos-sa-20250721-sfos-rce | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sophos firewall firmware | < 21.0.2 |
CPE
Remediation
| |
| sophos firewall | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 17, 2025 | Initial Analysis | [email protected] |
| Jul 21, 2025 | New CVE Received | [email protected] |