CVE-2020-29574: CyberoamOS (CROS) SQL Injection Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2025-02-06. EPSS: 4.7% chance of exploitation in the next 30 days.

An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.

Affected products

  • Sophos CyberoamOS: up to and including 2020-12-04

Published 2020-12-11. Last modified 2026-08-15.