CVE-2014-5503: Cyberoam OS

High severity, CVSS 10.0. EPSS: 2% chance of exploitation in the next 30 days.

SQL injection vulnerability in the Guest Login Portal in the Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote attackers to execute arbitrary SQL commands via the add_guest_user opcode.

Affected products

  • Cyberoam Cyberoam OS: up to and including 10.4; up to and including 10.6.1

Published 2014-10-07. Last modified 2026-06-17.