CVE-2014-2850
Sophos Web Appliance Firmware < 3.8.1.1 - OS Command Injection
Title source: ruleDescription
The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary commands via shell metacharacters in the address parameter.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremoteunix
https://www.exploit-db.com/exploits/32789
References (5)
Scores
EPSS
0.7572
EPSS Percentile
98.9%
Details
CWE
CWE-78
Status
published
Products (50)
sophos/web_appliance
sophos/web_appliance_firmware
3.7.8
sophos/web_appliance_firmware
3.0.0
sophos/web_appliance_firmware
3.0.1
sophos/web_appliance_firmware
3.0.1.1
sophos/web_appliance_firmware
3.0.2
sophos/web_appliance_firmware
3.0.3
sophos/web_appliance_firmware
3.0.4
sophos/web_appliance_firmware
3.0.5
sophos/web_appliance_firmware
3.0.5.1
... and 40 more
Published
Apr 11, 2014
Tracked Since
Feb 18, 2026