An SQL injection vulnerability in the legacy (transparent) SMTP proxy of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to remote code execution, if a quarantining policy is active for Email and SFOS was upgraded from a version older than 21.0 GA.
The vulnerability (CWE-89) lies in the legacy transparent SMTP proxy component of Sophos Firewall. An attacker can inject malicious SQL queries through this component, which, combined with an active email quarantine policy and following a previous SFOS system update from a version older than 21.0 GA, leads to arbitrary code execution on the device. The network vector (AV:N) without authentication requirement (PR:N) means that the exploit can be performed remotely over the network.
Successful exploitation of this vulnerability allows an attacker to execute remote code (RCE) on a Sophos Firewall device, which may result in complete takeover of the device, breach of confidentiality, integrity and availability of protected resources.
Update Sophos Firewall to version 21.0 MR2 (21.0.2) or newer. Detailed instructions are available in the official security advisory from the vendor: https://www.sophos.com/en-us/security-advisories/sophos-sa-20250721-sfos-rce
Sophos Firewall versions older than 21.0 MR2 (21.0.2), provided both conditions are met simultaneously: active email quarantine policy AND the SFOS system was previously updated from a version older than 21.0 GA.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSophos Firewall
HWSophosall versionsSophos Firewall Firmware
OSSophos< 21.0.2
Related vulnerabilities
Code injection w Sophos Firewall — RCE przez User Portal i Webadmin
Sophos Firewall SPX – pre-auth RCE przez zapis dowolnych plików
Słabe dane uwierzytelniające SSH w Sophos Firewall – nieautoryzowany dostęp uprzywilejowany
Pre-auth SQL injection w Sophos Firewall umożliwiający RCE
A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1...