CVE-2025-6704
An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to pre-auth remote code execution, if a specific configuration of SPX is enabled in combination with the firewall running in High Availability (HA) mode.
Vendor
Product
CWE
Yayın Tarihi
2025-07-21 14:15:30
Güncelleme
2025-08-18 20:15:16
Source Identifier
security-alert@sophos.com
KEV Date Added
-