Junglewise Threat Intelligence

CVE-2020-29574: CyberoamOS (CROS) SQL Injection Vulnerability

CVE-2020-29574 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-02-06

Vendors: Sophos.

Executive brief

CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin interface that allows an unauthenticated, remote attacker to execute arbitrary SQL statements. The vulnerability was reported as being exploited in the wild and the product has since reached end-of-life (EoL).

Affected products

  • Sophos CyberoamOS (CROS) through 2020-12-04

Timeline

  • 2020-12-11: disclosed: NVD Published Date
  • 2025-02-06: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-02-27: other: CISA KEV remediation due date