Skip to content
COOEY

FAIL › dossier

Sophos

VENDOR

· dossier confidence 20%

Sophos is a cybersecurity vendor with a concerning history of critical and high-severity remote code execution vulnerabilities in its firewall and web appliance products, particularly in management interfaces. The company has demonstrated recurring issues with input validation and authentication bypasses across multiple product lines.

PROFILE
Categorycybersecurity vendorWhat they doSophos provides cybersecurity solutions including firewalls, antivirus, and endpoint protection for organizations. Websitehttps://www.sophos.com ↗
SECURITY POSTURE

Sophos has a poor security track record with multiple high and critical remote code execution vulnerabilities across its firewall and web appliance products between 2020 and 2022, indicating systemic issues in input validation and authentication bypasses.

Notable failures
  • CVE-2020-12271 critical RCE in SFOS via SQL injection
  • CVE-2020-29574 high RCE in CyberoamOS via SQL injection
  • CVE-2020-15069 high RCE in XG Firewall via buffer overflow
  • CVE-2023-1671 high RCE in Web Appliance via command injection
  • CVE-2022-3236 high RCE in Firewall via code injection
  • CVE-2022-1040 high auth bypass in Firewall User Portal
Patterns: repeated unpatched RCE vulnerabilities in web management interfaces; SQL injection and command injection in admin portals; authentication bypasses leading to RCE in user-facing portals
FAILURE HISTORY · 8
DATEEVENTSEVSUMMARY
2022-03-25 CVE-2020-25223 high Sophos SG UTM WebAdmin had a remote code execution vulnerability that was actively exploited in the wild.
2022-03-31 CVE-2022-1040 high Sophos Firewall's User Portal and Webadmin suffered an authentication bypass vulnerability enabling remote code execution.
2025-02-06 CVE-2020-15069 high Sophos XG Firewalls were vulnerable to remote code execution via a bookmark feature, actively exploited in the wild.
2025-02-06 CVE-2020-29574 high Sophos's CyberoamOS had a remotely exploitable SQL injection vulnerability allowing unauthorized SQL execution without authentication.
2023-11-16 CVE-2023-1671 high Sophos Web Appliance Command Injection Vulnerability
2022-09-23 CVE-2022-3236 high Sophos Firewall exposed to remote code execution through User Portal and Webadmin.
2021-11-03 CVE-2020-12271 critical Sophos firewalls were vulnerable to SQL injection, potentially allowing attackers to steal credentials and execute code remotely.
2020-12-11 CVE-2020-29574 critical CVE-2020-29574: An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
Vulnerability allows remote code execution and credential exfiltration when exposed on WAN, indicating a critical flaw in Sophos SFOS firmware.
synthesissevere-fallout-0.60
Unauthenticated SQL injection in Cyberoam OS WebAdmin represents a critical failure in vendor security posture, allowing remote arbitrary SQL execution without authentication, indicating severe neglig
cvefeed.io ↗severe-fallout+0.00
Neutral CISA KEV catalog listing; no vendor-specific sentiment expressed.
cooey ↗severe-fallout-0.80
Critical SQL injection flaw enabling remote code execution and credential theft when admin/portal services are exposed on WAN.
"Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords"
www.cvefind.com ↗severe-fallout+0.00
Neutral CVE database listing; no vendor-specific sentiment expressed.
talosintelligence.com ↗severe-fallout+0.00
Neutral threat intelligence site; no vendor-specific sentiment expressed.
app.opencve.io ↗severe-fallout+0.00
Neutral CVE database listing; no vendor-specific sentiment expressed.
vulnpedia.com ↗severe-fallout+0.00
Neutral vulnerability reference site; no vendor-specific sentiment expressed.
securityonline.info ↗severe-fallout+0.00
Neutral security news site; no vendor-specific sentiment expressed.
www.cvefind.com ↗severe-fallout+0.00
Neutral coverage; no specific commentary on vendor handling or impact beyond listing CVE metadata.
xposedornot.com ↗severe-fallout+0.00
Irrelevant; no mention of Cyberoam, CVE-2020-29574, or vendor response.
dailysecurityreview.com ↗severe-fallout+0.00
Irrelevant; discusses SK Telecom breach unrelated to Cyberoam or this CVE.
cvefeed.io ↗severe-fallout+0.00
Irrelevant; discusses CISA KEV catalog without specific vendor commentary on Cyberoam.
dailysecurityreview.com ↗severe-fallout+0.00
Irrelevant; discusses Roundcube webmail RCE unrelated to Cyberoam or this CVE.
nypost.com ↗severe-fallout+0.00
Irrelevant; discusses unrelated legal case with no security vendor commentary.
cooey ↗severe-fallout-0.80
Severe vulnerability in Cyberoam OS WebAdmin allows unauthenticated remote SQL injection, exposing systems to arbitrary data manipulation and potential full compromise.
"An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely."
Open questions: Sophos's current patching SLA for critical RCE vulnerabilities · Whether recent AI-native products inherit the same injection vulnerabilities as legacy products
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-17 04:33:16.506001+00:00