CVE-2016-7786: Sophos Cyberoam CR25ING UTM Firmware

High severity, CVSS 8.8. EPSS: 7% chance of exploitation in the next 30 days.

Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via direct object reference, as demonstrated by a request for Licenseinformation.jsp. This is fixed in 10.6.5.

Affected products

  • Sophos Cyberoam CR25ING UTM Firmware: version 10.6.2 only

Published 2017-04-07. Last modified 2026-06-17.