CVE-2025-10159: Sophos AP6 Series Wireless Access Points

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

An authentication bypass vulnerability allows remote attackers to gain administrative privileges on Sophos AP6 Series Wireless Access Points older than firmware version 1.7.2563 (MR7).

Affected products

  • Sophos AP6 Series Wireless Access Points: before 1.7.2563 (MR7) (fixed in 1.7.2563 (MR7))

Published 2025-09-09. Last modified 2026-06-17.