Massive Firewall Vulnerabilities Exposed: Sophos and SonicWall Devices at Risk of Remote Code Execution!

Listen to this Post

Featured Image

🚨 Introduction: Why This Alert Matters

A wave of critical vulnerabilities has shaken the cybersecurity landscape, affecting two major network security providers—Sophos and SonicWall. These newly discovered flaws could allow attackers to remotely execute malicious code on firewalls and Secure Mobile Access (SMA) appliances, putting thousands of networks at immediate risk. With CVSS scores as high as 9.8, these vulnerabilities aren’t just technical slip-ups—they’re full-blown gateways for hackers to breach organizations. If left unpatched, they could lead to total control of network infrastructure, data breaches, and operational paralysis.

Security professionals, IT admins, and cybersecurity enthusiasts must understand what’s at stake. Let’s break down what’s happening, what Sophos and SonicWall have revealed, and how organizations can shield themselves from this looming threat.

🧨 Critical Security Breakdown: What You Need to Know

Both Sophos Firewall and SonicWall’s SMA 100 Series have been found to contain severe vulnerabilities that attackers can exploit to achieve remote code execution (RCE)—a worst-case scenario in cybersecurity.

Sophos Firewall Vulnerabilities:

Sophos disclosed five major vulnerabilities:

CVE-2025-6704 (CVSS 9.8): Arbitrary file writing via SPX PDF feature. Exploitable in HA mode with certain configurations.
CVE-2025-7624 (CVSS 9.8): SQL injection vulnerability in legacy SMTP proxy, affects systems upgraded from pre-21.0 GA versions.
CVE-2025-7382 (CVSS 8.8): Command injection in WebAdmin. Affects auxiliary HA devices with OTP enabled.
CVE-2024-13974 (CVSS 8.1): DNS manipulation via Up2Date logic flaw. Allows full RCE if exploited.
CVE-2024-13973 (CVSS 6.8): SQL injection in WebAdmin post-auth, enabling code execution.

Affected versions include:

Sophos Firewall v21.5 GA and older (for CVE-2025-6704, 7624, 7382)

Sophos Firewall v21.0 GA and older (for CVE-2024-13974, 13973)

While CVE-2025-6704 affects about 0.05% of devices, and CVE-2025-7624 affects around 0.73%, the risk remains massive due to the potential impact of even a single compromised firewall.

SonicWall SMA 100 Series Vulnerability:

CVE-2025-40599 (CVSS 9.1): Critical vulnerability in web management interface allowing arbitrary file upload and RCE. Impacts SMA 210, 410, and 500v devices.

Though not yet actively exploited, Google’s Threat Intelligence Group (GTIG) warns of a sophisticated group (UNC6148) using fully patched SMA 100 devices to install a backdoor called OVERSTEP.

SonicWall has patched this issue in version 10.2.2.1-90sv and recommends immediate hardening actions:

Disable remote management on external interfaces.

Reset passwords and rebind OTPs.

Enforce multi-factor authentication (MFA).

Enable Web Application Firewall (WAF).

Inspect logs for suspicious behavior.

Virtual appliances like SMA 500v also require a full reinstall from the updated OVA file and a manual config restore to ensure safety.

🧠 What Undercode Say: Expert Analysis and Deep Dive

These vulnerabilities mark a stark reminder that cybersecurity in modern appliances is a moving target. Despite routine patches and updates, attackers are increasingly focusing on edge devices like firewalls and VPN gateways—where trust is highest and visibility is lowest.

The Reality of High CVSS Scores:

With multiple CVEs scoring 8.0 or above, this is not a routine advisory. Anything over CVSS 9.0 implies near-effortless exploitation with severe consequences—especially when pre-authentication flaws are involved.

CVE-2025-6704 and CVE-2025-7624 could allow unauthenticated attackers to execute arbitrary code if specific configurations are in place—meaning some setups are more vulnerable than others. Still, even niche exploitation paths can be weaponized at scale.

Targeting Legacy and HA Configurations:

Both vendors are seeing attackers target legacy systems, upgraded versions, and high-availability (HA) modes, revealing a new trend in “version-drift” exploitation—where attackers go after inconsistencies during upgrade cycles. These flaws show that upgrading to newer firmware versions doesn’t always eliminate old vulnerabilities if certain components remain untouched.

SMA Devices as Prime Targets:

SonicWall’s SMA 100 devices are especially attractive to threat actors due to their remote access role in organizations. The discovery of OVERSTEP, a stealthy backdoor that evades detection even on patched systems, is deeply concerning. It signals an increase in nation-state-level actors targeting edge infrastructure.

What Should Organizations Do Now?

Patch immediately. Delaying updates can mean exposing your infrastructure to known, documented vulnerabilities.

Audit configurations, especially HA setups and legacy components.

Enable MFA everywhere and monitor authentication logs.

Reset OTPs and refresh administrative credentials.

Check logs and endpoint behavior for signs of lateral movement.

✅ Fact Checker Results

✅ All CVEs cited are officially documented by NIST and vendor advisories.
✅ Sophos and SonicWall have both issued patches, urging immediate updates.

✅ GTIG confirmed threat group

🔮 Prediction: The Next Wave of Firewall Attacks is Coming

As enterprise edge devices grow more complex and multifunctional, attackers will increasingly exploit misconfigurations and legacy paths—especially in HA and hybrid setups. Expect:

A rise in attacks targeting firewall upgrade missteps.

Surge in nation-state actors focusing on remote access points.

Backdoors like OVERSTEP becoming stealthier and more persistent.

Organizations must move beyond patching—adopting continuous monitoring, zero trust principles, and proactive anomaly detection. The age of “set-and-forget” firewalls is over.

Cybersecurity isn’t just about defense anymore—it’s about visibility, control, and readiness for the next breach attempt.

References:

Reported By: thehackernews.com
Extra Source Hub:
https://www.medium.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin