Executive brief
CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin interface that allows an unauthenticated, remote attacker to execute arbitrary SQL statements. The vulnerability was reported as being exploited in the wild and the product has since reached end-of-life (EoL).
Affected products
- Sophos CyberoamOS (CROS) through 2020-12-04
Timeline
- 2020-12-11: disclosed: NVD Published Date
- 2025-02-06: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-02-27: other: CISA KEV remediation due date