Vulnerability Description
A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achieving pre-auth code execution on High Availability (HA) auxiliary devices, if OTP authentication for the admin user is enabled.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sophos | Firewall Firmware | < 21.0.2 |
| Sophos | Firewall | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-7382?
CVE-2025-7382 is a vulnerability with a CVSS score of 8.8 (HIGH). A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achieving pre-auth code execution on High Availability (HA) auxili...
How severe is CVE-2025-7382?
CVE-2025-7382 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-7382?
Check the references section above for vendor advisories and patch information. Affected products include: Sophos Firewall Firmware, Sophos Firewall.