Sophos has patched an authentication bypass vulnerability in its AP6 Series Wireless Access Points. The flaw could allow attackers to gain administrator-level privileges. The company discovered the issue during internal security testing and has released a software update to address it.

The security vulnerability allows an attacker with network access to bypass authentication checks via the access point's management IP address. A successful exploit would grant the malicious user administrative privileges on the affected device. This elevated access could be used to control the access point, intercept or manipulate network traffic, disrupt wireless network connectivity , or use the compromised device as a launching pad for further attacks within the network.
See also: Chrome update fixes critical RCE vulnerability
Sophos said the vulnerability was discovered by its own team, underscoring a proactive approach to product security. The nature of the flaw, which requires access to the management interface, suggests that the main risk comes from attackers already on the local network.
Sophos: Vulnerable versions and update
The vulnerability affects Sophos AP6 Series Wireless Access Points running software versions prior to 1.7.2563 (MR7). To address the issue, Sophos has included a fix in software version 1.7.2563 (MR7), released after August 11, 2025. Administrators are advised to verify that their access points are running this version or a later version.

Any organization using older versions of software remains vulnerable and must upgrade to receive the security fix and protect their networks from potential exploitation.
See also: Microsoft Patch Tuesday September 2025: 81 Vulnerabilities Fixed
For most customers, the remediation process is automatic. Sophos AP6 appliances are configured by default to install updates automatically, meaning that patched software will be applied without requiring manual intervention.
This default policy ensures that the majority of users are seamlessly protected. However, customers who have intentionally chosen not to receive automatic updates must take manual action. These users are required to upgrade their AP6 Series software to version 1.7.2563 (MR7) or a later version.
Failure to upgrade leaves wireless access points exposed to this critical authentication bypass risk.
Security vulnerabilities: A constant risk
The case of Sophos with the AP6 Series Wireless Access Points clearly shows how fragile even the most “innocent” pieces of a corporate infrastructure can be. An access point, often neglected in the context of security, can become a gateway for complete control of the network if an attacker gains access.
See also: Windows BitLocker vulnerability allows elevation of privilege attack

The vulnerability, discovered by Sophos itself, also demonstrates the value of proactive research by manufacturers themselves. At a time when the cybersecurity industry is often accused of delays and bug coverage, the company's quick response sets a positive example.
For organizations, the critical message is that update management is not a secondary process but a core pillar of protection. Those with automatic updates enabled are in a safe zone. In contrast, businesses that have opted for manual updates, often for control or compatibility reasons, need to act immediately – otherwise they are leaving their access points open to abuse.
See also: Zoom Security Update – Fixing Multiple Vulnerabilities
In an environment where attacking edge devices is becoming an increasingly popular tactic, such incidents are a wake-up call: perimeter security is no less critical than the center of the network. On the contrary, it is the first point that attackers test.
