Critical severity9.8CISA KEVNVD Advisory· Published Sep 25, 2020· Updated Jun 17, 2026
CVE-2020-25223
CVE-2020-25223
Description
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:sophos:unified_threat_management:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:sophos:unified_threat_management:*:*:*:*:*:*:*:*range: <9.511
- cpe:2.3:a:sophos:unified_threat_management:9.511:-:*:*:*:*:*:*
- cpe:2.3:a:sophos:unified_threat_management:9.607:-:*:*:*:*:*:*
- cpe:2.3:a:sophos:unified_threat_management:9.705:-:*:*:*:*:*:*
- Sophos/SG UTMdescription
Patches
Vulnerability mechanics
References
6- packetstormsecurity.com/files/164697/Sophos-UTM-WebAdmin-SID-Command-Injection.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.secpod.com/blog/remote-code-execution-in-sophos-utm/nvdExploitThird Party Advisory
- community.sophos.com/b/security-blognvdNot ApplicableVendor Advisory
- community.sophos.com/b/security-blog/posts/advisory-resolved-rce-in-sg-utm-webadmin-cve-2020-25223nvdVendor Advisory
- cwe.mitre.org/data/definitions/78.htmlnvdTechnical Description
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.