← Vulnerability feed

Vulnerability record · CVE-2016-9554 · published 28 January 2017

CVE-2016-9554: Sophos web appliance command injection vulnerability

Sophos · Web Appliance

The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. These vulnerabilities occur in MgrDiagnosticTools.php (/controllers/MgrDiagnosticTools.php), in the component responsible for performing diagnostic tests with the UNIX wget utility. The application doesn't properly escape the information passed in the 'url' variable before calling the executeCommand class function ($this->dtObj->executeCommand). This function calls exec() with unsanitized user input allowing for remote command injection. The page that contains the vulnerabilities, /controllers/MgrDiagnosticTools.php, is accessed by a built-in command answered by the administrative interface. The command that calls to that vulnerable page (passed in the 'section' parameter) is: 'configuration'. Exploitation of this vulnerability yields shell access to the remote machine under the 'spiderman' user account.

7.2 CVSS 3.0 High EPSS 25% · top 2.2% CWE-77 · Command injection
7.2CVSS 3.0 base score, v2 9.0
25%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. These vulnerabilities occur in MgrDiagnosticTools.php (/controllers/MgrDiagnosticTools.php), in the component responsible for performing diagnostic tests with the UNIX wget utility. The application doesn't properly escape the information passed in the 'url' variable before calling the executeCommand class function ($this->dtObj->executeCommand). This function calls exec() with unsanitized user input allowing for remote command injection. The page that contains the vulnerabilities, /controllers/MgrDiagnosticTools.php, is accessed by a built-in command answered by the administrative interface. The command that calls to that vulnerable page (passed in the 'section' parameter) is: 'configuration'. Exploitation of this vulnerability yields shell access to the remote machine under the 'spiderman' user account.

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-9554 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-1671Sophos Web Appliance pre-auth command injection in warn-proceed handlerSophos Web Appliance versions older than 4.3.10.4 contain a command injection flaw in the warn-proceed handler. Because it is reachable without authe…KEVEPSS 100%analysed9.8CVE-2017-6182Sophos web appliance os command injection vulnerabilityIn Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote comman…EPSS 17%9.3CVE-2013-2642Sophos web appliance firmware os command injection vulnerabilitySophos Web Appliance before 3.7.8.2 allows (1) remote attackers to execute arbitrary commands via shell metacharacters in the client-ip parameter to …EPSS 6.9%8.5CVE-2014-2849Sophos Web Appliance change_password access control flawSophos Web Appliance before 3.8.2 fails to properly restrict the Change Password dialog box (change_password), letting a remote authenticated user ch…EPSS 60%analysed8.5CVE-2014-2850Sophos Web Appliance netinterface page OS command injectionThe netinterface configuration page in Sophos Web Appliance before 3.8.2 fails to sanitize the address parameter, allowing shell metacharacters to be…EPSS 58%analysed8.1CVE-2017-6412Sophos web appliance vulnerabilityIn Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310.EPSS 7.5%7.2CVE-2022-4934Sophos web appliance command injection vulnerabilityA post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4 allows administrators to exec…EPSS 1.8%7.2CVE-2017-6183Sophos web appliance command injection vulnerabilityIn Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's configuration utilities for adding (and detecting) Active Directory servers …EPSS 3.2%

Source: NIST National Vulnerability Database (record CVE-2016-9554), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.