CVE-2025-7382 HIGH

CVE-2025-7382

Vendor Sophos
Product Sophos Firewall
Weakness CWE-78
Published July 21, 2025
Last update July 21, 2025

CVSS base score

8.8/10
Attack vector Adjacent
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achieving pre-auth code execution on High Availability (HA) auxiliary devices, if OTP authentication for the admin user is enabled.

Key dates

02Disclosure timeline

July 21, 2025 CVE published
July 21, 2025 Record updated