Vulnerability Database

301,027

Total vulnerabilities in the database

CVE-2025-7382

A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achieving pre-auth code execution on High Availability (HA) auxiliary devices, if OTP authentication for the admin user is enabled.

  • Published: Jul 21, 2025
  • Updated: Jul 22, 2025
  • CVE: CVE-2025-7382
  • Exploit:

No technical information available.

No CWE or OWASP classifications available.