Unrated severityNVD Advisory· Published Jul 21, 2025· Updated Jul 21, 2025
CVE-2025-6704
CVE-2025-6704
Description
An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to pre-auth remote code execution, if a specific configuration of SPX is enabled in combination with the firewall running in High Availability (HA) mode.
Affected products
2- Range: <21.0.2
- Sophos/Sophos Firewallv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.