CVE-2025-7382: Command Injection
A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achieving pre-auth code execution on High Availability (HA) auxiliary devices, if OTP authentication for the admin user is enabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Sophos Firewall WebAdminto a version that resolves this vulnerability.Fixed in 21.0.2 - Configuration
Disable OTP authentication for the admin user to mitigate the condition described for versions older than 21.0 MR2 (21.0.2), where enabled OTP allows adjacent attackers to achieve pre-auth code execution on HA auxiliary devices.
Sophos Firewall WebAdmin OTP authentication for the admin user = disabled - Compensating control
If you are on Sophos Firewall versions older than 21.0 MR2 (21.0.2), restrict access to WebAdmin and HA auxiliary devices (e.g., via network segmentation/ACLs) so adjacent attackers cannot reach the WebAdmin interface pre-auth.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7382?
CVE-2025-7382 is classified as a critical command injection vulnerability.
How do I fix CVE-2025-7382?
To fix CVE-2025-7382, upgrade your Sophos Firewall to version 21.0.2 or later.
Who is affected by CVE-2025-7382?
CVE-2025-7382 affects users of Sophos Firewall versions older than 21.0 MR2.
What type of attack does CVE-2025-7382 enable?
CVE-2025-7382 enables adjacent attackers to achieve pre-auth code execution on affected devices.
Does CVE-2025-7382 require OTP authentication to be exploited?
Yes, CVE-2025-7382 can be exploited if OTP authentication for the admin user is enabled.