Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Sophos and SonicWall Patch Critical RCE Flaws Affecting Firewalls and SMA 100 Devices

Posted on July 24, 2025July 24, 2025 By CWS

Jul 24, 2025Ravie LakshmananNetwork Safety / Vulnerability
Sophos and SonicWall have alerted customers of crucial safety flaws in Sophos Firewall and Safe Cell Entry (SMA) 100 Collection home equipment that may very well be exploited to realize distant code execution.
The 2 vulnerabilities impacting Sophos Firewall are listed beneath –

CVE-2025-6704 (CVSS rating: 9.8) – An arbitrary file writing vulnerability within the Safe PDF eXchange (SPX) function can result in pre-auth distant code execution, if a particular configuration of SPX is enabled together with the firewall working in Excessive Availability (HA) mode
CVE-2025-7624 (CVSS rating: 9.8) – An SQL injection vulnerability within the legacy (clear) SMTP proxy can result in distant code execution, if a quarantining coverage is lively for Electronic mail and SFOS was upgraded from a model older than 21.0 GA

Sophos stated CVE-2025-6704 impacts about 0.05% of gadgets, whereas CVE-2025-7624 impacts as many as 0.73% of gadgets. Each vulnerabilities have been addressed alongside a high-severity command injection vulnerability within the WebAdmin part (CVE-2025-7382, CVSS rating: 8.8) that might end in pre-auth code execution on Excessive Availability (HA) auxiliary gadgets, if OTP authentication for the admin person is enabled.
Additionally patched by the corporate are two different vulnerabilities –

CVE-2024-13974 (CVSS rating: 8.1) – A enterprise logic vulnerability within the Up2Date part can result in attackers controlling the firewall’s DNS atmosphere to realize distant code execution
CVE-2024-13973 (CVSS rating: 6.8) – A post-auth SQL injection vulnerability in WebAdmin can doubtlessly result in directors attaining arbitrary code execution

The U.Okay. Nationwide Cyber Safety Centre (NCSC) has been credited with discovering and reporting each CVE-2024-13974 and CVE-2024-13973. The problems have an effect on the next variations –

CVE-2024-13974 – Impacts Sophos Firewall v21.0 GA (21.0.0) and older
CVE-2024-13973 – Impacts Sophos Firewall v21.0 GA (21.0.0) and older
CVE-2025-6704 – Impacts Sophos Firewall v21.5 GA (21.5.0) and older
CVE-2025-7624 – Impacts Sophos Firewall v21.5 GA (21.5.0) and older
CVE-2025-7382 – Impacts Sophos Firewall v21.5 GA (21.5.0) and older

The disclosure comes as SonicWall detailed a crucial bug within the SMA 100 Collection net administration interface (CVE-2025-40599, CVSS rating: 9.1) {that a} distant attacker with administrative privileges can exploit to add arbitrary information and doubtlessly obtain distant code execution.
The flaw impacts SMA 100 Collection merchandise (SMA 210, 410, 500v) and has been addressed in model 10.2.2.1-90sv.
SonicWall additionally identified that whereas the vulnerability has not been exploited, there exists a possible danger in mild of a current report from the Google Menace Intelligence Group (GTIG), which discovered proof of a risk actor dubbed UNC6148 leveraging fully-patched SMA 100 sequence gadgets to deploy a backdoor known as OVERSTEP.

In addition to making use of the fixes, the corporate can also be recommending that clients of SMA 100 Collection gadgets perform the next steps –

Disable distant administration entry on the external-facing interface (X1) to scale back the assault floor
Reset all passwords and reinitialize OTP (One-Time Password) binding for customers and directors on the equipment
Implement multi-factor authentication (MFA) for all customers
Allow Internet Software Firewall (WAF) on SMA 100

Organizations utilizing SMA 100 Collection gadgets are additionally suggested to evaluate equipment logs and connection historical past for anomalies and verify for any indicators of unauthorized entry.
Organizations utilizing the SMA 500v digital product are required to backup the OVA file, export the configuration, take away the prevailing digital machine and all related digital disks and snapshots, reinstall the brand new OVA from SonicWall utilizing a hypervisor, and restore the configuration.

The Hacker News Tags:Affecting, Critical, Devices, Firewalls, Flaws, Patch, RCE, SMA, SonicWall, Sophos

Post navigation

Previous Post: NoName057(16)’s Hackers Attacked 3,700 Unique Devices Over Last Thirteen Months
Next Post: Threat Actors Weaponizing .hwp Files to Deliver RokRAT Malware

Related Posts

CISA Adds Three Exploited Vulnerabilities to KEV Catalog Affecting Citrix and Git The Hacker News
Citrix Releases Emergency Patches for Actively Exploited CVE-2025-6543 in NetScaler ADC The Hacker News
5 Critical Questions For Adopting an AI Security Solution The Hacker News
HOOK Android Trojan Adds Ransomware Overlays, Expands to 107 Remote Commands The Hacker News
Over 250 Magento Stores Hit Overnight as Hackers Exploit New Adobe Commerce Flaw The Hacker News
Hackers Exploit SharePoint Zero-Day Since July 7 to Steal Keys, Maintain Persistent Access The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • $1M WhatsApp Hack Flops: Only Low-Risk Bugs Disclosed to Meta After Pwn2Own Withdrawal
  • AI-Powered Ransomware Is the Emerging Threat That Could Bring Down Your Organization
  • YouTube Ghost Malware Network With 3,000+ Malicious Videos Attacking Users to Deploy Malware
  • Agenda Ransomware Actors Deploying Linux RAT on Windows Systems Targeting VMware Deployments
  • New Text Message Based Phishing Attack from China Targeting Users Around the Globe

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • $1M WhatsApp Hack Flops: Only Low-Risk Bugs Disclosed to Meta After Pwn2Own Withdrawal
  • AI-Powered Ransomware Is the Emerging Threat That Could Bring Down Your Organization
  • YouTube Ghost Malware Network With 3,000+ Malicious Videos Attacking Users to Deploy Malware
  • Agenda Ransomware Actors Deploying Linux RAT on Windows Systems Targeting VMware Deployments
  • New Text Message Based Phishing Attack from China Targeting Users Around the Globe

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News