CVE-2020-25223

CRITICAL KEV NUCLEI

Sophos Unified Threat Management < 9.511 - OS Command Injection

Title source: rule

Description

A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11

Exploits (3)

nomisec WORKING POC 11 stars
by darrenmartyn · remote
https://github.com/darrenmartyn/sophucked
nomisec WORKING POC 2 stars
by maguireja · poc
https://github.com/maguireja/CVE-2020-25223
metasploit WORKING POC EXCELLENT
by Justin Kennedy, wvu · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/sophos_utm_webadmin_sid_cmd_injection.rb

Nuclei Templates (1)

Sophos UTM Preauth - Remote Code Execution
CRITICALby gy741
Shodan: http.title:"securepoint utm"
FOFA: title="securepoint utm"

Scores

CVSS v3 9.8
EPSS 0.9442
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

CISA KEV 2022-03-25
VulnCheck KEV 2022-03-25
InTheWild.io 2022-03-25
ENISA EUVD EUVD-2020-17913

Classification

CWE
CWE-78
Status published

Affected Products (4)

sophos/unified_threat_management < 9.511
sophos/unified_threat_management
sophos/unified_threat_management
sophos/unified_threat_management

Timeline

Published Sep 25, 2020
KEV Added Mar 25, 2022
Tracked Since Feb 18, 2026