Sophos Firewall version v19.0 MR1 and older is vulnerable to code injection in the User Portal and Webadmin, allowing a remote unauthenticated attacker to execute arbitrary code.
id: CVE-2022-3236
info:
name: Sophos Firewall <= 19.0 MR1 - Remote Code Execution
author: daffa
...