CRITICAL🇵🇱 Wersja polska

CVE-2025-7624

CVSS 9.8v3.1pub. 2025-07-21upd. 2025-11-17

An SQL injection vulnerability in the legacy (transparent) SMTP proxy of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to remote code execution, if a quarantining policy is active for Email and SFOS was upgraded from a version older than 21.0 GA.

🤖 AI Analysis
How it works

The vulnerability (CWE-89) lies in the legacy transparent SMTP proxy component of Sophos Firewall. An attacker can inject malicious SQL queries through this component, which, combined with an active email quarantine policy and following a previous SFOS system update from a version older than 21.0 GA, leads to arbitrary code execution on the device. The network vector (AV:N) without authentication requirement (PR:N) means that the exploit can be performed remotely over the network.

Impact

Successful exploitation of this vulnerability allows an attacker to execute remote code (RCE) on a Sophos Firewall device, which may result in complete takeover of the device, breach of confidentiality, integrity and availability of protected resources.

Mitigation & patch

Update Sophos Firewall to version 21.0 MR2 (21.0.2) or newer. Detailed instructions are available in the official security advisory from the vendor: https://www.sophos.com/en-us/security-advisories/sophos-sa-20250721-sfos-rce

Who is affected

Sophos Firewall versions older than 21.0 MR2 (21.0.2), provided both conditions are met simultaneously: active email quarantine policy AND the SFOS system was previously updated from a version older than 21.0 GA.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Sophos Firewall

    HW
    Sophos
    all versions
  • Sophos Firewall Firmware

    OS
    Sophos
    < 21.0.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCESQLiFirewall
CWE
References

Related vulnerabilities

CVE-2022-3236CRITICAL9.8⚠ KEVPL ✓same product

Code injection w Sophos Firewall — RCE przez User Portal i Webadmin

CVE-2025-6704CRITICAL9.8PL ✓same product

Sophos Firewall SPX – pre-auth RCE przez zapis dowolnych plików

CVE-2024-12728CRITICAL9.8PL ✓same product

Słabe dane uwierzytelniające SSH w Sophos Firewall – nieautoryzowany dostęp uprzywilejowany

CVE-2024-12727CRITICAL9.8PL ✓same product

Pre-auth SQL injection w Sophos Firewall umożliwiający RCE

CVE-2024-13974HIGH8.1same product

A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1...