Vulnerability Database

301,027

Total vulnerabilities in the database

CVE-2025-7624

An SQL injection vulnerability in the legacy (transparent) SMTP proxy of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to remote code execution, if a quarantining policy is active for Email and SFOS was upgraded from a version older than 21.0 GA.

  • Published: Jul 21, 2025
  • Updated: Jul 22, 2025
  • CVE: CVE-2025-7624
  • Exploit:

No technical information available.

No CWE or OWASP classifications available.