CVE-2020-37095: Cyberoam Authentication Client
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
Cyberoam Authentication Client 2.1.2.7 contains a buffer overflow vulnerability that allows remote attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) memory. Attackers can craft a malicious input in the 'Cyberoam Server Address' field to trigger a bind TCP shell on port 1337 with system-level access.
Affected products
- Cyberoam Cyberoam Authentication Client: version 2.1.2.7 only
Published 2026-02-07. Last modified 2026-06-17.