CVE-2025-6704: OS Command Injection
An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to pre-auth remote code execution, if a specific configuration of SPX is enabled in combination with the firewall running in High Availability (HA) mode.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Sophos Firewall (Secure PDF eXchange - SPX)to a version that resolves this vulnerability.Fixed in 21.0.2 - Configuration
Ensure the SPX feature is not configured in the specific way that enables the arbitrary file writing vulnerability when the firewall is running in High Availability (HA) mode.
Sophos Firewall (Secure PDF eXchange - SPX feature) SPX configuration (specific configuration described as enabling arbitrary file writing) = Disable the specific SPX configuration that enables arbitrary file writing in combination with HA mode
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6704?
CVE-2025-6704 is considered a critical vulnerability due to its potential for pre-auth remote code execution.
How do I fix CVE-2025-6704?
To fix CVE-2025-6704, upgrade Sophos Firewall to version 21.0.2 or later.
Which versions of Sophos Firewall are affected by CVE-2025-6704?
CVE-2025-6704 affects all Sophos Firewall versions prior to 21.0.2.
Can CVE-2025-6704 be exploited if SPX is disabled?
If SPX is disabled, CVE-2025-6704 cannot be exploited.
Does CVE-2025-6704 impact the firewall's High Availability mode?
Yes, CVE-2025-6704 specifically affects Sophos Firewall running in High Availability mode when SPX is configured.