📦 Firewall Firmware

by Sophos

🔍 What is Firewall Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-6704

CRITICAL CVSS 9.8 Jul 21, 2025

This vulnerability allows unauthenticated attackers to write arbitrary files to Sophos Firewall systems, potentially leading to remote code execution. It affects Sophos Firewall versions older than 21...

CVE-2025-7624

CRITICAL CVSS 9.8 Jul 21, 2025

An SQL injection vulnerability in Sophos Firewall's legacy SMTP proxy allows remote attackers to execute arbitrary code on affected systems. This affects Sophos Firewall versions older than 21.0 MR2 w...

CVE-2024-12727

CRITICAL CVSS 9.8 Dec 19, 2024

This critical vulnerability allows unauthenticated attackers to execute SQL injection attacks against Sophos Firewall's email protection feature. Successful exploitation can lead to database access an...

CVE-2024-13974

HIGH CVSS 8.1 Jul 21, 2025

This vulnerability in Sophos Firewall's Up2Date component allows attackers who control the firewall's DNS environment to achieve remote code execution. It affects Sophos Firewall versions older than 2...

CVE-2024-12729

HIGH CVSS 8.8 Dec 19, 2024

This is a post-authentication code injection vulnerability in Sophos Firewall's User Portal that allows authenticated users to execute arbitrary code remotely. It affects Sophos Firewall versions olde...

CVE-2024-13973

MEDIUM CVSS 6.8 Jul 21, 2025

This CVE describes a post-authentication SQL injection vulnerability in Sophos Firewall's WebAdmin interface. Attackers with administrative credentials can exploit this to execute arbitrary SQL comman...