CVE-2024-13973: Sophos Firewall Firmware

High severity, CVSS 7.2. EPSS: 10% chance of exploitation in the next 30 days.

A post-auth SQL injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR1 (21.0.1) can potentially lead to administrators achieving arbitrary code execution.

Affected products

  • Sophos Firewall Firmware: before 21.0.1 (fixed in 21.0.1)

Published 2025-07-21. Last modified 2026-06-17.