A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    22 Oct 2025, 00:17
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
21 Oct 2025, 20:17
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
21 Oct 2025, 19:18
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
Information
                Published : 2020-09-25 04:23
Updated : 2025-10-22 00:17
NVD link : CVE-2020-25223
Mitre link : CVE-2020-25223
CVE.ORG link : CVE-2020-25223
JSON object : View
Products Affected
                sophos
- unified_threat_management
CWE
                
                    
                        
                        CWE-78
                        
            Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
