Unrated severityNVD Advisory· Published Jul 21, 2025· Updated Jul 21, 2025
CVE-2025-7382
CVE-2025-7382
Description
A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achieving pre-auth code execution on High Availability (HA) auxiliary devices, if OTP authentication for the admin user is enabled.
Affected products
2- Range: <=21.0.1
- Sophos/Sophos Firewallv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.