CVE-2025-7382
8.8Sophos · Sophos Firewall
A command injection vulnerability in the WebAdmin interface of Sophos Firewall allows adjacent attackers to achieve unauthenticated remote code execution on auxiliary high availability devices.
Executive summary
A critical command injection vulnerability in Sophos Firewall WebAdmin permits adjacent, unauthenticated attackers to execute arbitrary code on auxiliary devices in a high availability configuration.
Vulnerability
This is an OS command injection vulnerability (CWE-78) within the WebAdmin interface, specifically impacting systems where OTP authentication for the admin user is enabled. The vulnerability allows an unauthenticated, adjacent attacker to execute arbitrary commands on auxiliary High Availability (HA) nodes.
Business impact
Successful exploitation of this flaw grants an attacker full control over the affected firewall appliance. This could lead to complete system compromise, unauthorized access to internal network traffic, and potential lateral movement into protected environments. Given the CVSS score of 8.8, this represents a high-severity risk to business continuity and data integrity.
Remediation
Immediate Action: Update all Sophos Firewall installations to version 21.0 MR2 (21.0.2) or later immediately to resolve the injection flaw.
Proactive Monitoring: Review system logs for suspicious activity originating from the adjacent network segment, specifically focusing on unexpected command execution attempts or unauthorized access to the WebAdmin interface.
Compensating Controls: Restrict access to the WebAdmin interface to trusted management subnets only and ensure that HA traffic is isolated from untrusted network segments to prevent adjacent exploitation.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability poses a significant risk to the security of the network perimeter. Organizations using Sophos Firewall in high availability modes must prioritize the update to version 21.0 MR2 (21.0.2) as the primary mitigation. Failure to apply this patch leaves auxiliary devices vulnerable to unauthenticated remote code execution, which could be leveraged to bypass security controls entirely.