CVE-2020-37095: Cyberoam Authentication Client

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Cyberoam Authentication Client 2.1.2.7 contains a buffer overflow vulnerability that allows remote attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) memory. Attackers can craft a malicious input in the 'Cyberoam Server Address' field to trigger a bind TCP shell on port 1337 with system-level access.

Affected products

  • Cyberoam Cyberoam Authentication Client: version 2.1.2.7 only

Published 2026-02-07. Last modified 2026-06-17.