CVE-2014-2850

Sophos Web Appliance Firmware < 3.8.1.1 - OS Command Injection

Title source: rule

Description

The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary commands via shell metacharacters in the address parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremoteunix
https://www.exploit-db.com/exploits/32789

Scores

EPSS 0.7572
EPSS Percentile 98.9%

Details

CWE
CWE-78
Status published
Products (50)
sophos/web_appliance
sophos/web_appliance_firmware 3.7.8
sophos/web_appliance_firmware 3.0.0
sophos/web_appliance_firmware 3.0.1
sophos/web_appliance_firmware 3.0.1.1
sophos/web_appliance_firmware 3.0.2
sophos/web_appliance_firmware 3.0.3
sophos/web_appliance_firmware 3.0.4
sophos/web_appliance_firmware 3.0.5
sophos/web_appliance_firmware 3.0.5.1
... and 40 more
Published Apr 11, 2014
Tracked Since Feb 18, 2026