CRITICAL🇵🇱 Wersja polska

CVE-2025-6704

CVSS 9.8v3.1pub. 2025-07-21upd. 2025-08-18

An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to pre-auth remote code execution, if a specific configuration of SPX is enabled in combination with the firewall running in High Availability (HA) mode.

🤖 AI Analysis
How it works

The flaw lies in the ability to write arbitrary files (arbitrary file writing) in the SPX module. The vulnerability is active only when the SPX feature is enabled and simultaneously the device operates in High Availability (HA) mode. The combination of these two configuration conditions creates an unauthenticated network-accessible attack vector, corresponding to CWE-78 (command injection) classification and potentially leading to execution of arbitrary system commands.

Impact

An attacker without any privileges can remotely execute arbitrary code on the firewall device, gaining full control over the system, including access to sensitive data, ability to modify configuration, and potential interception of network traffic protected by the device.

Mitigation & patch

Sophos Firewall should be updated to version 21.0 MR2 (21.0.2) or newer. As a temporary workaround, if immediate update is not possible, consider disabling the SPX feature or High Availability (HA) mode until the patch is deployed. Details available in the official security advisory: https://www.sophos.com/en-us/security-advisories/sophos-sa-20250721-sfos-rce

Who is affected

Sophos Firewall in all versions prior to 21.0 MR2 (21.0.2), while simultaneously meeting both conditions: SPX feature enabled and High Availability (HA) mode active.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Sophos Firewall

    HW
    Sophos
    all versions
  • Sophos Firewall Firmware

    OS
    Sophos
    < 21.0.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEFirewallCommand Injection
CWE
References

Related vulnerabilities

CVE-2022-3236CRITICAL9.8⚠ KEVPL ✓same product

Code injection w Sophos Firewall — RCE przez User Portal i Webadmin

CVE-2025-7624CRITICAL9.8PL ✓same product

SQL Injection w Sophos Firewall SMTP Proxy prowadzące do RCE

CVE-2024-12728CRITICAL9.8PL ✓same product

Słabe dane uwierzytelniające SSH w Sophos Firewall – nieautoryzowany dostęp uprzywilejowany

CVE-2024-12727CRITICAL9.8PL ✓same product

Pre-auth SQL injection w Sophos Firewall umożliwiający RCE

CVE-2024-13974HIGH8.1same product

A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1...