A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version 21.0 MR1 (21.0.1).
https://latesthackingnews.com/2025/01/03/sophos-firewall-vulnerabilities-could-allow-remote-attacks/
https://www.securityweek.com/sophos-patches-critical-firewall-vulnerabilities/
https://thehackernews.com/2024/12/sophos-fixes-3-critical-firewall-flaws.html
https://securityaffairs.com/172179/security/sophos-firewall-critical-vulnerabilities.html