A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version 21.0 MR1 (21.0.1).
2024-12-19T21:15:07.983
2025-11-12T19:08:33.593
Analyzed
CVSSv3.1: 8.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | sophos | firewall_firmware | < 21.0.1 | Yes |
| Hardware | sophos | firewall | - | No |