An information disclosure vulnerability in Webadmin allows an unauthenticated remote attacker to read the device serial number in Sophos Firewall version v18.5 MR2 and older.
https://www.sophos.com/en-us/security-advisories/sophos-sa-20220328-sfos-18-5-3