CVE-2016-7786: Sophos Cyberoam CR25ING UTM Firmware
High severity, CVSS 8.8. EPSS: 7% chance of exploitation in the next 30 days.
Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via direct object reference, as demonstrated by a request for Licenseinformation.jsp. This is fixed in 10.6.5.
Affected products
- Sophos Cyberoam CR25ING UTM Firmware: version 10.6.2 only
Published 2017-04-07. Last modified 2026-06-17.