← Vulnerability feed

Vulnerability record · CVE-2025-7382 · published 21 July 2025

CVE-2025-7382: Sophos firewall firmware os command injection vulnerability

Sophos · Firewall Firmware

A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achieving pre-auth code execution on High Availability (HA) auxiliary devices, if OTP authentication for the admin user is enabled.

8.8 CVSS 3.1 High EPSS 4.8% · top 8.4% CWE-78 · OS command injection
8.8CVSS 3.1 base score
4.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achieving pre-auth code execution on High Availability (HA) auxiliary devices, if OTP authentication for the admin user is enabled.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-7382 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-6704Sophos firewall firmware os command injection vulnerabilityAn arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to…EPSS 9.5%9.8CVE-2025-7624Sophos firewall firmware sql injection vulnerabilityAn SQL injection vulnerability in the legacy (transparent) SMTP proxy of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to remote cod…EPSS 8.5%9.8CVE-2024-12727Sophos firewall firmware sql injection vulnerabilityA pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the …EPSS 1.4%9.8CVE-2024-12728Sophos firewall firmware vulnerabilityA weak credentials vulnerability potentially allows privileged system access via SSH to Sophos Firewall older than version 20.0 MR3 (20.0.3).EPSS 0.94%8.8CVE-2024-12729Sophos firewall firmware code injection vulnerabilityA post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version…EPSS 1.3%8.4CVE-2021-25267Sophos firewall firmware cross-site scripting vulnerabilityMultiple XSS vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 19.0 GA.EPSS 1.1%8.4CVE-2021-25268Sophos firewall firmware cross-site scripting vulnerabilityMultiple XSS vulnerabilities in Webadmin allow for privilege escalation from MySophos admin to SFOS admin in Sophos Firewall older than version 19.0 …EPSS 0.91%8.1CVE-2024-13974Sophos firewall firmware vulnerabilityA business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers controlling the…EPSS 7.4%

Source: NIST National Vulnerability Database (record CVE-2025-7382), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.