CVE-2022-1040

CRITICAL KEV RANSOMWARE NUCLEI

Sophos Firewall < 18.5.3 - Unauthenticated Remote Code Execution

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2022-1040 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 31, 2022, with confirmed use in ransomware campaigns. EIP tracks 8 public exploits from researchers including Aryan Chehreghani, jam620, killvxk. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in Sophos XG115w Firewall 17.0.10 MR-10 by manipulating the 'mode' parameter in a POST request to bypass authentication and gain unauthorized access to the firewall management interface.

Description

An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.

Exploits (8)

exploitdb WORKING POC
by Aryan Chehreghani · textwebappshardware
https://www.exploit-db.com/exploits/51006

This exploit demonstrates an authentication bypass vulnerability in Sophos XG115w Firewall 17.0.10 MR-10 by manipulating the 'mode' parameter in a POST request to bypass authentication and gain unauthorized access to the firewall management interface.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Sophos XG115w Firewall 17.0.10 MR-10
No auth needed
Prerequisites: Network access to the target firewall · Knowledge of the target's IP address and port
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 17 stars
by jam620 · remote
https://github.com/jam620/Sophos-Vulnerability

This repository provides a detailed analysis and proof-of-concept for CVE-2022-1040, an authentication bypass vulnerability in Sophos Firewall. It includes steps for identifying vulnerable targets using Shodan and a curl-based check for vulnerability confirmation.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Sophos Firewall (Sophos XG115w Firewall 17.0.10 MR-10)
No auth needed
Prerequisites: Shodan API access · VPS for scanning · jq for parsing
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 17 stars
by killvxk · poc
https://github.com/killvxk/CVE-2022-1040

This repository contains a proof-of-concept exploit for CVE-2022-1040, which targets a vulnerability in Sophos Firewall. The exploit uses a crafted HTTP POST request to trigger the vulnerability, potentially leading to remote code execution.

Classification
Working Poc 80%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Sophos Firewall
No auth needed
Prerequisites: Network access to the target Sophos Firewall
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 3 stars
by Keith-amateur · remote
https://github.com/Keith-amateur/cve-2022-1040

This PoC demonstrates an authentication bypass vulnerability in Sophos Firewall by intercepting and modifying HTTPS POST requests to the web console. It uses a man-in-the-middle proxy to inject a crafted payload that bypasses authentication.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Sophos Firewall (version not specified)
No auth needed
Prerequisites: Access to the target network · Ability to intercept HTTPS traffic
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 2 stars
by jackson5sec · remote
https://github.com/jackson5sec/CVE-2022-1040

This repository contains a writeup for CVE-2022-1040, an authentication bypass vulnerability in Sophos XG115w Firewall 17.0.10 MR-10. It includes a description and a screenshot but lacks exploit code or technical details.

Classification
Writeup 80%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Theoretical
Target: Sophos XG115w Firewall 17.0.10 MR-10
No auth needed
Prerequisites: Network access to the target firewall
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec STUB 1 stars
by Cyb3rEnthusiast · poc
https://github.com/Cyb3rEnthusiast/CVE-2022-1040

The repository claims to provide a PoC for CVE-2022-1040, an auth bypass and RCE vulnerability in Sophos Firewall, but only contains a README and a placeholder script requiring payment for access.

Classification
Stub 90%
Attack Type
Rce
Complexity
Theoretical
Reliability
Theoretical
Target: Sophos Firewall v18.5 MR3 (18.5.3) and older
No auth needed
Prerequisites: Network access to vulnerable Sophos Firewall
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec STUB
by xMr110 · remote
https://github.com/xMr110/CVE-2022-1040

The repository contains only a README.md file with minimal information (CVE-2022-1040 title) and no exploit code or technical details. It appears to be a placeholder or incomplete submission.

Classification
Stub 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unknown
No auth needed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by michealadams30 · remote
https://github.com/michealadams30/CVE-2022-1040

The repository contains only a README.md file mentioning CVE-2022-1040, a Sophos exploit, without providing any actual exploit code or technical details. It lacks actionable proof-of-concept material.

Classification
Writeup 30%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: Sophos (version 17.0.10 MR-10)
No auth needed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Sophos Firewall <=18.5 MR3 - Remote Code Execution
CRITICALVERIFIEDby For3stCo1d
Shodan: http.title:"Sophos" || http.title:"sophos"
FOFA: title="sophos"

References (4)

Core 4
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/51006

Scores

CVSS v3 9.8
EPSS 0.9444
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2022-03-31
VulnCheck KEV 2022-03-21
InTheWild.io 2021-07-12
ENISA EUVD EUVD-2022-24387
Ransomware Use Confirmed
Status published
Products (1)
sophos/sfos < 18.5.3
Published Mar 25, 2022
KEV Added Mar 31, 2022
Tracked Since Feb 18, 2026