SQL Injection Vulnerability in Sophos Firewall by Sophos
CVE-2025-7624

9.8CRITICAL

Key Information:

Vendor

Sophos

Vendor
CVE Published:
21 July 2025

What is CVE-2025-7624?

An SQL injection vulnerability exists in the legacy (transparent) SMTP proxy of Sophos Firewall. If a quarantining policy is active for Email and the firmware was upgraded from a version older than 21.0 GA, this weakness could potentially allow remote code execution, posing significant risks to organizational security. Users should update to version 21.0 MR2 (21.0.2) or later to mitigate the threat effectively.

Affected Version(s)

Sophos Firewall 0 < 21.0 MR2 (21.0.2)

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7624 : SQL Injection Vulnerability in Sophos Firewall by Sophos