CVE-2025-7382
A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achieving pre-auth code execution on High Availability (HA) auxiliary devices, if OTP authentication for the admin user is enabled.
Vendor
Product
CWE
Yayın Tarihi
2025-07-21 14:15:30
Güncelleme
2025-11-17 16:22:35
Source Identifier
security-alert@sophos.com
KEV Date Added
-