S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2020-25223 Scanner

CVE-2020-25223 scanner - Remote Code Execution (RCE) vulnerability in Sophos SG UTM

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2020-25223
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Sophos SG UTM is a popular security product used by companies and organizations to protect their network and keep it safe from cybercriminals. This product is an all-in-one security gateway that provides the necessary tools for web protection, email filtering, network security, and wireless security. Sophos SG UTM is designed to offer high-level safeguards to companies of all sizes, from small businesses to large enterprises, who want to ensure their digital assets remain secure.

CVE-2020-25223 is a remote code execution vulnerability that was recently detected in Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11. This vulnerability arises due to an incorrect validation of user input in the WebAdmin of the product. Attackers can exploit this vulnerability to execute arbitrary code, thereby compromising the security of the system.

When this vulnerability is exploited, cybercriminals can gain unauthorized access to sensitive information, take control of the network, and cause severe damage to the company's reputation. They can also launch malware attacks and steal confidential data, resulting in significant financial losses for the organization.

Thanks to s4e.io, individuals and businesses alike can easily learn about potential vulnerabilities in their digital assets. The pro features of s4e.io enable users to quickly identify potential threats and take appropriate action to protect their networks, systems, and data. By being proactive in identifying and addressing vulnerabilities, organizations can maintain their digital assets' safety and security.

 

REFERENCES

Solution Advice

To protect against CVE-2020-25223, Sophos recommends that users update their systems immediately with available patches. Additionally, users are advised to follow these precautions:

  • Monitor network activity for any signs of attacks
  • Secure servers and endpoints to prevent unauthorized access
  • Use strong passwords for all accounts and enable multi-factor authentication
  • Educate all employees on cybersecurity practices to prevent phishing attacks

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-25223 scanner - Remote Code Execution (RCE) vulnerability in Sophos SG UTM | S4E