CVE-2025-7624: SQL Injection
An SQL injection vulnerability in the legacy (transparent) SMTP proxy of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to remote code execution, if a quarantining policy is active for Email and SFOS was upgraded from a version older than 21.0 GA.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Sophos Firewall (legacy transparent SMTP proxy)to a version that resolves this vulnerability.Fixed in 21.0.2 - Compensating control
Ensure a quarantining policy for Email is not active when legacy transparent SMTP proxy exposure is possible (SQL injection can lead to RCE if a quarantining policy is active and SFOS was upgraded from before 21.0 GA to a version older than 21.0 MR2).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7624?
CVE-2025-7624 is classified as a critical vulnerability due to its potential to lead to remote code execution.
How do I fix CVE-2025-7624?
To fix CVE-2025-7624, upgrade Sophos Firewall to version 21.0 MR2 (21.0.2) or later.
Which versions of Sophos Firewall are affected by CVE-2025-7624?
CVE-2025-7624 affects Sophos Firewall versions prior to 21.0 MR2 (21.0.2).
What type of vulnerability is CVE-2025-7624?
CVE-2025-7624 is an SQL injection vulnerability that can lead to remote code execution.
What conditions must be met for CVE-2025-7624 to be exploited?
CVE-2025-7624 can be exploited if a quarantining policy is active for Email and the firewall was upgraded from a version older than 21.0 GA.