CVE-2025-7382: Sophos Firewall Firmware

High severity, CVSS 8.8. EPSS: 4.8% chance of exploitation in the next 30 days.

A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achieving pre-auth code execution on High Availability (HA) auxiliary devices, if OTP authentication for the admin user is enabled.

Affected products

  • Sophos Firewall Firmware: before 21.0.2 (fixed in 21.0.2)

Published 2025-07-21. Last modified 2026-06-17.