CVE-2018-16118: Sophos SFOS

High severity, CVSS 8.1. EPSS: 3.7% chance of exploitation in the next 30 days.

A shell escape vulnerability in /webconsole/APIController in the API Configuration component of Sophos XG firewall 17.0.8 MR-8 allows remote attackers to execute arbitrary OS commands via shell metachracters in the "X-Forwarded-for" HTTP header.

Affected products

  • Sophos SFOS: up to and including 16.0; version 16.5 only; version 17.0 only; version 17.0.8 only; version 17.1 only

Published 2019-06-20. Last modified 2026-06-17.