SQL Injection Vulnerability in Sophos Firewall by Sophos
CVE-2025-7624

9.8CRITICAL

Key Information:

Vendor

Sophos

Vendor
CVE Published:
21 July 2025

Badges

đź“° News Worthy

What is CVE-2025-7624?

An SQL injection vulnerability exists in the legacy (transparent) SMTP proxy of Sophos Firewall. If a quarantining policy is active for Email and the firmware was upgraded from a version older than 21.0 GA, this weakness could potentially allow remote code execution, posing significant risks to organizational security. Users should update to version 21.0 MR2 (21.0.2) or later to mitigate the threat effectively.

Affected Version(s)

Sophos Firewall 0 < 21.0 MR2 (21.0.2)

News Articles

Sophos and SonicWall Patch Critical RCE Flaws Affecting Firewalls and SMA 100 Devices

Sophos and SonicWall patched critical RCE flaws in firewall and SMA 100 products affecting select users.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • đź“°

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7624 : SQL Injection Vulnerability in Sophos Firewall by Sophos